CVE-2020-0551
Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
Does this matter?
Lower severity and a low EPSS score (1.04%). Track it; it rarely justifies an emergency change on its own.
Description
Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. The list of affected products is provided in intel-sa-00334: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00334.html
- CVSS 3.1
- 5.6 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 1.04% probability · 62th percentile
- CISA KEV
- Not listed
- Affected
- intel/atom c2308 · intel/atom c2316 · intel/atom c2338 · intel/atom c2350 · intel/atom c2358 · intel/atom c2508 · intel/atom c2516 · intel/atom c2518 · intel/atom c2530 · intel/atom c2538 · intel/atom c2550 · intel/atom c2558 · intel/atom c2718 · intel/atom c2730 · intel/atom c2738 · intel/atom c2750 · intel/atom c2758 · intel/atom e3805 · intel/atom e3815 · intel/atom e3825 · +40 more
- Source
- secure@intel.com
References
- https://security.netapp.com/advisory/ntap-20200320-0002/Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00334.htmlVendor Advisory
- https://security.netapp.com/advisory/ntap-20200320-0002/Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00334.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.