CVE-2018-3640

UnknownEPSS 7.56%

Last modified

CVE-2018-3640 is a vulnerability of currently unknown severity. Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.. EPSS estimates a 7.56% chance of exploitation in the next 30 days.

Description

Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.

Metrics

EPSS Probability
7.56%

93.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelAtom Cc2308
IntelAtom Cc3308
IntelAtom Cc3338
IntelAtom Cc3508
IntelAtom Cc3538
IntelAtom Cc3558
IntelAtom Cc3708
IntelAtom Cc3750
IntelAtom Cc3758
IntelAtom Cc3808
IntelAtom Cc3830
IntelAtom Cc3850
IntelAtom Cc3858
IntelAtom Cc3950
IntelAtom Cc3955
IntelAtom Cc3958
IntelAtom Ee3805
IntelAtom Ee3815
IntelAtom Ee3825
IntelAtom Ee3826
IntelAtom Ee3827
IntelAtom Ee3845
IntelAtom Zz2420
IntelAtom Zz2460
IntelAtom Zz2480
IntelAtom Zz2520
IntelAtom Zz2560
IntelAtom Zz2580
IntelAtom Zz2760
IntelAtom Zz3460
IntelAtom Zz3480
IntelAtom Zz3530
IntelAtom Zz3560
IntelAtom Zz3570
IntelAtom Zz3580
IntelAtom Zz3590
IntelAtom Zz3735d
IntelAtom Zz3735e
IntelAtom Zz3735f
IntelAtom Zz3735g
IntelAtom Zz3736f
IntelAtom Zz3736g
IntelAtom Zz3740
IntelAtom Zz3740d
IntelAtom Zz3745
IntelAtom Zz3745d
IntelAtom Zz3770
IntelAtom Zz3770d
IntelAtom Zz3775
IntelAtom Zz3775d

Showing 50 of 500 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-3640?
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
How severe is CVE-2018-3640?
Severity scoring for CVE-2018-3640 is pending analysis. The EPSS model estimates a 7.56% probability of exploitation in the next 30 days.
How do I fix CVE-2018-3640?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-3640?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST