CVE-2018-3620

MEDIUMCVSS 5.6/10EPSS 5.58%

Last modified

CVE-2018-3620 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.. EPSS estimates a 5.58% chance of exploitation in the next 30 days.

Description

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.

Metrics

CVSS 3.1
5.6/10

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS Probability
5.58%

91.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelCore I3330e
IntelCore I3330m
IntelCore I3330um
IntelCore I3350m
IntelCore I3370m
IntelCore I3380m
IntelCore I3380um
IntelCore I3390m
IntelCore I3530
IntelCore I3540
IntelCore I3550
IntelCore I3560
IntelCore I32100
IntelCore I32100t
IntelCore I32102
IntelCore I32105
IntelCore I32115c
IntelCore I32120
IntelCore I32120t
IntelCore I32125
IntelCore I32130
IntelCore I32310e
IntelCore I32310m
IntelCore I32312m
IntelCore I32328m
IntelCore I32330e
IntelCore I32330m
IntelCore I32340ue
IntelCore I32348m
IntelCore I32350m
IntelCore I32357m
IntelCore I32365m
IntelCore I32367m
IntelCore I32370m
IntelCore I32375m
IntelCore I32377m
IntelCore I33110m
IntelCore I33115c
IntelCore I33120m
IntelCore I33120me
IntelCore I33130m
IntelCore I33210
IntelCore I33217u
IntelCore I33217ue
IntelCore I33220
IntelCore I33220t
IntelCore I33225
IntelCore I33227u
IntelCore I33229y
IntelCore I33240

Showing 50 of 463 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-3620?
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.
How severe is CVE-2018-3620?
CVE-2018-3620 has a CVSS score of 5.6/10 (MEDIUM severity). The EPSS model estimates a 5.58% probability of exploitation in the next 30 days.
How do I fix CVE-2018-3620?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-3620?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST