CVE-2018-3639

MEDIUMCVSS 5.5/10EPSS 60.63%

Last modified

CVE-2018-3639 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.. EPSS estimates a 60.63% chance of exploitation in the next 30 days.

Description

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

Metrics

CVSS 3.1
5.5/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
60.63%

99.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
IntelAtom Cc2308
IntelAtom Cc3308
IntelAtom Cc3338
IntelAtom Cc3508
IntelAtom Cc3538
IntelAtom Cc3558
IntelAtom Cc3708
IntelAtom Cc3750
IntelAtom Cc3758
IntelAtom Cc3808
IntelAtom Cc3830
IntelAtom Cc3850
IntelAtom Cc3858
IntelAtom Cc3950
IntelAtom Cc3955
IntelAtom Cc3958
IntelAtom Ee3805
IntelAtom Ee3815
IntelAtom Ee3825
IntelAtom Ee3826
IntelAtom Ee3827
IntelAtom Ee3845
IntelAtom X5-E3930All versions
IntelAtom X5-E3940All versions
IntelAtom X7-E3950All versions
IntelAtom Zz2420
IntelAtom Zz2460
IntelAtom Zz2480
IntelAtom Zz2520
IntelAtom Zz2560
IntelAtom Zz2580
IntelAtom Zz2760
IntelAtom Zz3460
IntelAtom Zz3480
IntelAtom Zz3530
IntelAtom Zz3560
IntelAtom Zz3570
IntelAtom Zz3580
IntelAtom Zz3590
IntelAtom Zz3735d
IntelAtom Zz3735e
IntelAtom Zz3735f
IntelAtom Zz3735g
IntelAtom Zz3736f
IntelAtom Zz3736g
IntelAtom Zz3740
IntelAtom Zz3740d
IntelAtom Zz3745
IntelAtom Zz3745d
IntelAtom Zz3770

Showing 50 of 626 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-3639?
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
How severe is CVE-2018-3639?
CVE-2018-3639 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 60.63% probability of exploitation in the next 30 days.
How do I fix CVE-2018-3639?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-3639?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST