SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-40982

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

MEDIUM 6.5EPSS 3.05%

Does this matter?

Lower severity and a low EPSS score (3.05%). Track it; it rarely justifies an emergency change on its own.

Description

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS
3.05% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-1342, CWE-203
Affected
redhat/enterprise linux · xen/xen · intel/microcode · intel/xeon e-2314 firmware · intel/xeon e-2324g firmware · intel/xeon e-2334 firmware · intel/xeon e-2374g firmware · intel/xeon e-2336 firmware · intel/xeon e-2356g firmware · intel/xeon e-2386g firmware · intel/xeon e-2378 firmware · intel/xeon e-2378g firmware · intel/xeon e-2388g firmware · intel/xeon w-1350 firmware · intel/xeon w-1350p firmware · intel/xeon w-1370 firmware · intel/xeon w-1370p firmware · intel/xeon w-1390t firmware · intel/xeon w-1390 firmware · intel/xeon w-1390p firmware · +40 more
Source
secure@intel.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.