PT-2020-17000 · Xen+1 · Xen+1
Andreas Kogler
+6
·
Published
2020-11-10
·
Updated
2024-06-15
·
CVE-2020-28368
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Xen versions through 4.14.x
Description
The issue allows guest OS administrators to obtain sensitive information, such as AES keys from outside the guest, via a side-channel attack on a power/energy monitoring interface, also known as a "Platypus" attack.
Recommendations
To resolve the issue, change the access control for each power/energy monitoring interface in Xen.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Xen