CVE-2022-29901
ECS: Exposure of Sensitive Information to an Unauthorized Actor (CVE-2022-29901)
mediumEPSS 5.0%
Affected
- Dell/ECS
3.8.1.0..*
Description
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.
Source: BSI CSAFBSI WID Portalcvelistv5
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
DellECS
3.8.1.0Metrics
92.0 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
medium
96.94
no public PoC known
5.6
Published
2022-07-12 00:00 UTC
CWE-200
Weakness classes (CWE)
CWE-200Class
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
cwe.mitre.org →
References & sources
- https://comsec.ethz.ch/retbleed
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00702.html
- http://www.openwall.com/lists/oss-security/2022/07/12/2mailing-list
- http://www.openwall.com/lists/oss-security/2022/07/12/4mailing-list
- http://www.openwall.com/lists/oss-security/2022/07/12/5mailing-list
- http://www.openwall.com/lists/oss-security/2022/07/13/1mailing-list
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M27MB3QFNIJV4EQQSXWARHP3OGX6CR6K/vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4RW5FCIYFNCQOEFJEUIRW3DGYW7CWBG/vendor-advisory
- https://www.debian.org/security/2022/dsa-5207vendor-advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00011.htmlmailing-list
- https://security.netapp.com/advisory/ntap-20221007-0007/
- https://lists.debian.org/debian-lts-announce/2022/12/msg00034.htmlmailing-list
- https://www.secpod.com/blog/retbleed-intel-and-amd-processor-information-disclosure-vulnerability/
- https://security.gentoo.org/glsa/202402-07vendor-advisory