CVE-2022-29901

ECS: Exposure of Sensitive Information to an Unauthorized Actor (CVE-2022-29901)

mediumEPSS 5.0%

Affected

  • Dell/ECS 3.8.1.0..*

Description

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

DellECS
3.8.1.0

Metrics

5.6
Source: cna-v3
92.0 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
medium
no public PoC known
5.0 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2022-07-12 00:00 UTC
CWE-200

Weakness classes (CWE)

  • CWE-200Class

    Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

    cwe.mitre.org →

References & sources

Linked advisories