CVE-2017-5715
medium · 5.6Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
5.6
CVSS
74.0%
EPSS (exploit prob.)
99th
EPSS percentile
2018-01-04
Published
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Weaknesses
CWE-203
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| intel | atom_c | c2308 |
| intel | atom_c | c2316 |
| intel | atom_c | c2338 |
| intel | atom_c | c2350 |
| intel | atom_c | c2358 |
| intel | atom_c | c2508 |
| intel | atom_c | c2516 |
| intel | atom_c | c2518 |
| intel | atom_c | c2530 |
| intel | atom_c | c2538 |
| intel | atom_c | c2550 |
| intel | atom_c | c2558 |
| intel | atom_c | c2718 |
| intel | atom_c | c2730 |
| intel | atom_c | c2738 |
| intel | atom_c | c2750 |
| intel | atom_c | c2758 |
| intel | atom_c | c3308 |
| intel | atom_c | c3338 |
| intel | atom_c | c3508 |
| intel | atom_c | c3538 |
| intel | atom_c | c3558 |
| intel | atom_c | c3708 |
| intel | atom_c | c3750 |
| intel | atom_c | c3758 |
| intel | atom_c | c3808 |
| intel | atom_c | c3830 |
| intel | atom_c | c3850 |
| intel | atom_c | c3858 |
| intel | atom_c | c3950 |
| intel | atom_c | c3955 |
| intel | atom_c | c3958 |
| intel | atom_e | e3805 |
| intel | atom_e | e3815 |
| intel | atom_e | e3825 |
| intel | atom_e | e3826 |
| intel | atom_e | e3827 |
| intel | atom_e | e3845 |
| intel | atom_x3 | c3130 |
| intel | atom_x3 | c3200rk |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html
- http://nvidia.custhelp.com/app/answers/detail/a_id/4609
- http://nvidia.custhelp.com/app/answers/detail/a_id/4611
- http://nvidia.custhelp.com/app/answers/detail/a_id/4613
- http://nvidia.custhelp.com/app/answers/detail/a_id/4614
- http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html
- http://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.html
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt
- http://www.kb.cert.org/vuls/id/584653
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/102376
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-5715