CVE-2018-3615
intel core_i3: Sicherheitsluecke
highEPSS 6.3%
Description
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.
Source: cvelistv5NVD (NIST)
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
intelcore_i3
intelcore_i5
intelcore_i7
intelxeon_e3
intelxeon_e3_1220_v5
intelxeon_e3_1220_v6
intelxeon_e3_1225_v5
intelxeon_e3_1225_v6
intelxeon_e3_1230_v5
intelxeon_e3_1230_v6
intelxeon_e3_1235l_v5
intelxeon_e3_1240_v5
intelxeon_e3_1240_v6
intelxeon_e3_1240l_v5
intelxeon_e3_1245_v5
intelxeon_e3_1245_v6
intelxeon_e3_1260l_v5
intelxeon_e3_1268l_v5
intelxeon_e3_1270_v5
intelxeon_e3_1270_v6
intelxeon_e3_1275_v5
intelxeon_e3_1275_v6
intelxeon_e3_1280_v5
intelxeon_e3_1280_v6
intelxeon_e3_1285_v6
intelxeon_e3_1501l_v6
intelxeon_e3_1501m_v6
intelxeon_e3_1505l_v5
intelxeon_e3_1505l_v6
intelxeon_e3_1505m_v5
Metrics
93.4 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
high
106.35
no public PoC known
7.3
Published
2018-08-14 19:00 UTC
References & sources
- https://www.kb.cert.org/vuls/id/982149third-party-advisoryx_refsource_CERT-VN
- http://www.securitytracker.com/id/1041451vdb-entryx_refsource_SECTRACK
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0008x_refsource_CONFIRM
- http://www.securityfocus.com/bid/105080vdb-entryx_refsource_BID
- https://foreshadowattack.eu/x_refsource_MISC
- https://security.netapp.com/advisory/ntap-20180815-0001/x_refsource_CONFIRM
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180814-cpusidechannelvendor-advisoryx_refsource_CISCO
- https://support.f5.com/csp/article/K35558453x_refsource_CONFIRM
- http://support.lenovo.com/us/en/solutions/LEN-24163x_refsource_CONFIRM
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180815-01-cpu-enx_refsource_CONFIRM
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.htmlx_refsource_CONFIRM
- https://www.synology.com/support/security/Synology_SA_18_45x_refsource_CONFIRM
- https://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlmailing-listx_refsource_MLIST
- https://cert-portal.siemens.com/productcert/pdf/ssa-254686.pdfx_refsource_CONFIRM
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03874en_usx_refsource_CONFIRM
- https://software.intel.com/security-software-guidance/software-guidance/l1-terminal-faultx_refsource_CONFIRM
- https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfx_refsource_CONFIRM