CVE-2018-3615

intel core_i3: Sicherheitsluecke

Description

Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

intelcore_i3
intelcore_i5
intelcore_i7
intelxeon_e3
intelxeon_e3_1220_v5
intelxeon_e3_1220_v6
intelxeon_e3_1225_v5
intelxeon_e3_1225_v6
intelxeon_e3_1230_v5
intelxeon_e3_1230_v6
intelxeon_e3_1235l_v5
intelxeon_e3_1240_v5
intelxeon_e3_1240_v6
intelxeon_e3_1240l_v5
intelxeon_e3_1245_v5
intelxeon_e3_1245_v6
intelxeon_e3_1260l_v5
intelxeon_e3_1268l_v5
intelxeon_e3_1270_v5
intelxeon_e3_1270_v6
intelxeon_e3_1275_v5
intelxeon_e3_1275_v6
intelxeon_e3_1280_v5
intelxeon_e3_1280_v6
intelxeon_e3_1285_v6
intelxeon_e3_1501l_v6
intelxeon_e3_1501m_v6
intelxeon_e3_1505l_v5
intelxeon_e3_1505l_v6
intelxeon_e3_1505m_v5

Metrics

7.3
Source: nvd-v3
93.4 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
high
no public PoC known
6.3 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2018-08-14 19:00 UTC

References & sources

Linked advisories