VulnerabilityModified
CVE-2022-40982
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
MEDIUM 6.5EPSS 3.05%
Does this matter?
Lower severity and a low EPSS score (3.05%). Track it; it rarely justifies an emergency change on its own.
Description
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 3.05% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1342, CWE-203
- Affected
- redhat/enterprise linux · xen/xen · intel/microcode · intel/xeon e-2314 firmware · intel/xeon e-2324g firmware · intel/xeon e-2334 firmware · intel/xeon e-2374g firmware · intel/xeon e-2336 firmware · intel/xeon e-2356g firmware · intel/xeon e-2386g firmware · intel/xeon e-2378 firmware · intel/xeon e-2378g firmware · intel/xeon e-2388g firmware · intel/xeon w-1350 firmware · intel/xeon w-1350p firmware · intel/xeon w-1370 firmware · intel/xeon w-1370p firmware · intel/xeon w-1390t firmware · intel/xeon w-1390 firmware · intel/xeon w-1390p firmware · +40 more
- Source
- secure@intel.com
References
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.htmlExploit, Mitigation, Vendor Advisory
- https://access.redhat.com/solutions/7027704Third Party Advisory
- https://aws.amazon.com/security/security-bulletins/AWS-2023-007/Third Party Advisory
- https://downfall.pageExploit, Technical Description, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00013.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00026.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKKYIK2EASDNUV4I7EFJKNBVO3KCKGRR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKREYYTWUY7ZDNIB2N6H5BUJ3LE5VZPE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OL7WI2TJCWSZIQP2RIOLWHOKLM25M44J/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7WO5JM74YJSYAE5RBV4DC6A4YLEKWLF/
- https://security.netapp.com/advisory/ntap-20230811-0001/Third Party Advisory
- https://www.debian.org/security/2023/dsa-5474Mailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5475Mailing List, Third Party Advisory
- https://xenbits.xen.org/xsa/advisory-435.htmlMitigation, Third Party Advisory
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.htmlExploit, Mitigation, Vendor Advisory
- http://xenbits.xen.org/xsa/advisory-435.html
- https://access.redhat.com/solutions/7027704Third Party Advisory
- https://aws.amazon.com/security/security-bulletins/AWS-2023-007/Third Party Advisory
- https://downfall.pageExploit, Technical Description, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00013.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00026.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKKYIK2EASDNUV4I7EFJKNBVO3KCKGRR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKREYYTWUY7ZDNIB2N6H5BUJ3LE5VZPE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OL7WI2TJCWSZIQP2RIOLWHOKLM25M44J/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7WO5JM74YJSYAE5RBV4DC6A4YLEKWLF/
- https://security.netapp.com/advisory/ntap-20230811-0001/Third Party Advisory
- https://www.debian.org/security/2023/dsa-5474Mailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5475Mailing List, Third Party Advisory
- https://xenbits.xen.org/xsa/advisory-435.htmlMitigation, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.