PT-2018-1445 · Intel+8 · Intel Microprocessors+8

Published

2018-01-03

·

Updated

2020-08-24

·

CVE-2018-3620

CVSS v3.1

5.6

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Intel microprocessors (affected versions not specified)
Description The issue concerns systems with microprocessors that use speculative execution and address translations, potentially allowing unauthorized disclosure of information from the L1 data cache to an attacker with local user access. This can be achieved via a terminal page fault and side-channel analysis. The vulnerability is related to the speculative execution of commands and may allow an attacker to gain unauthorized access to the kernel memory or SMM memory by implementing a side-channel attack, enabling them to read data from the L1 cache where fragments of protected data remain after speculative execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2164
ALT-PU-2018-2165
ALT-PU-2018-2253
BDU:2018-00995
CESA-2018_2384
CESA-2018_2390
CVE-2018-3620
DLA-1481-1
DLA-1506-1
DLA-1529-1
DSA-4274-1
DSA-4279-1
DSA-4279-2
FREEBSD-SA-18_09
MGASA-2018-0344
MGASA-2018-0345
MGASA-2018-0346
MGASA-2018-0347
OPENSUSE-SU-2018_2404-1
OPENSUSE-SU-2018_2407-1
RHSA-2018:2384
RHSA-2018:2387
RHSA-2018:2388
RHSA-2018:2389
RHSA-2018:2390
RHSA-2018:2391
RHSA-2018:2392
RHSA-2018:2393
RHSA-2018:2394
RHSA-2018:2395
RHSA-2018:2396
RHSA-2018:2402
RHSA-2018:2403
RHSA-2018:2404
RHSA-2018:2602
RHSA-2018:2603
RHSA-2018_2384
RHSA-2018_2390
RHSA-2018_2395
RHSA-2018_2602
SUSE-SU-2018:2328-1
SUSE-SU-2018:2332-1
SUSE-SU-2018:2344-1
SUSE-SU-2018:2344-2
SUSE-SU-2018:2362-1
SUSE-SU-2018:2366-1
SUSE-SU-2018:2374-1
SUSE-SU-2018:2380-1
SUSE-SU-2018:2381-1
SUSE-SU-2018:2384-1
SUSE-SU-2018:2450-1
SUSE-SU-2018:2596-1
SUSE-SU-2018:2637-1
USN-3740-1
USN-3740-2
USN-3741-1
USN-3741-2
USN-3741-3
USN-3742-1
USN-3742-2
USN-3823-1

Affected Products

Alt Linux
Centos
Freebsd
Huawei Vrp
Intel Microprocessors
Red Hat
Suse
Ubuntu
Vmware Vcenter