SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-25368

Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context.

MEDIUM 4.7EPSS 0.30%

Does this matter?

Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.

Description

Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.

CVSS 3.1
4.7 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.30% probability · 22th percentile
CISA KEV
Not listed
Affected
amperecomputing/ampere altra max firmware · amperecomputing/ampere altra firmware · arm/neoverse-e1 firmware · arm/neoverse-v1 firmware · arm/cortex-a57 firmware · arm/cortex-a65 firmware · arm/cortex-a65ae firmware · arm/cortex-a72 firmware · arm/cortex-a73 firmware · arm/cortex-a75 firmware · arm/cortex-a76 firmware · arm/cortex-a76ae firmware · arm/cortex-a77 firmware · arm/cortex-a78 firmware · arm/cortex-a78ae firmware · arm/cortex-a78c firmware · arm/cortex-x1 firmware · arm/cortex-x2 firmware · arm/cortex-a710 firmware · arm/cortex-a15 firmware · +2 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.