CVE-2018-3615

HIGHCVSS 7.3/10EPSS 6.30%

Last modified

CVE-2018-3615 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.. EPSS estimates a 6.30% chance of exploitation in the next 30 days.

Description

Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.

Metrics

CVSS 3.1
7.3/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

EPSS Probability
6.30%

92.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelCore I36006u
IntelCore I36098p
IntelCore I36100
IntelCore I36100e
IntelCore I36100h
IntelCore I36100t
IntelCore I36100te
IntelCore I36100u
IntelCore I36102e
IntelCore I36157u
IntelCore I36167u
IntelCore I36300
IntelCore I36300t
IntelCore I36320
IntelCore I5650
IntelCore I5655k
IntelCore I5660
IntelCore I5661
IntelCore I5670
IntelCore I5680
IntelCore I56200u
IntelCore I56260u
IntelCore I56267u
IntelCore I56287u
IntelCore I56300hq
IntelCore I56300u
IntelCore I56350hq
IntelCore I56360u
IntelCore I56400
IntelCore I56400t
IntelCore I56402p
IntelCore I56440eq
IntelCore I56440hq
IntelCore I56442eq
IntelCore I56500
IntelCore I56500t
IntelCore I56500te
IntelCore I56585r
IntelCore I56600
IntelCore I56600k
IntelCore I56600t
IntelCore I56685r
IntelCore I7610e
IntelCore I7620le
IntelCore I7620lm
IntelCore I7620m
IntelCore I7620ue
IntelCore I7620um
IntelCore I7640lm
IntelCore I7640m

Showing 50 of 129 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-3615?
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.
How severe is CVE-2018-3615?
CVE-2018-3615 has a CVSS score of 7.3/10 (HIGH severity). The EPSS model estimates a 6.30% probability of exploitation in the next 30 days.
How do I fix CVE-2018-3615?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-3615?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST