CVE-2017-5753
medium · 5.6Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
5.6
CVSS
93.8%
EPSS (exploit prob.)
100th
EPSS percentile
2018-01-04
Published
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Weaknesses
CWE-203
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| intel | atom_c | c2308 |
| intel | atom_c | c2316 |
| intel | atom_c | c2338 |
| intel | atom_c | c2350 |
| intel | atom_c | c2358 |
| intel | atom_c | c2508 |
| intel | atom_c | c2516 |
| intel | atom_c | c2518 |
| intel | atom_c | c2530 |
| intel | atom_c | c2538 |
| intel | atom_c | c2550 |
| intel | atom_c | c2558 |
| intel | atom_c | c2718 |
| intel | atom_c | c2730 |
| intel | atom_c | c2738 |
| intel | atom_c | c2750 |
| intel | atom_c | c2758 |
| intel | atom_c | c3308 |
| intel | atom_c | c3338 |
| intel | atom_c | c3508 |
| intel | atom_c | c3538 |
| intel | atom_c | c3558 |
| intel | atom_c | c3708 |
| intel | atom_c | c3750 |
| intel | atom_c | c3758 |
| intel | atom_c | c3808 |
| intel | atom_c | c3830 |
| intel | atom_c | c3850 |
| intel | atom_c | c3858 |
| intel | atom_c | c3950 |
| intel | atom_c | c3955 |
| intel | atom_c | c3958 |
| intel | atom_e | e3805 |
| intel | atom_e | e3815 |
| intel | atom_e | e3825 |
| intel | atom_e | e3826 |
| intel | atom_e | e3827 |
| intel | atom_e | e3845 |
| intel | atom_x3 | c3130 |
| intel | atom_x3 | c3200rk |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html
- http://nvidia.custhelp.com/app/answers/detail/a_id/4609
- http://nvidia.custhelp.com/app/answers/detail/a_id/4611
- http://nvidia.custhelp.com/app/answers/detail/a_id/4613
- http://nvidia.custhelp.com/app/answers/detail/a_id/4614
- http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt
- http://www.kb.cert.org/vuls/id/584653
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.securityfocus.com/bid/102371
- http://www.securitytracker.com/id/1040071
- http://xenbits.xen.org/xsa/advisory-254.html
- https://access.redhat.com/errata/RHSA-2018:0292
- https://access.redhat.com/security/vulnerabilities/speculativeexecution
- https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/
- https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/
- https://cdrdv2.intel.com/v1/dl/getContent/685359
- https://cert-portal.siemens.com/productcert/pdf/ssa-505225.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf
- https://cert.vde.com/en-us/advisories/vde-2018-002
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-5753