CVE-2018-3693
Last modified
CVE-2018-3693 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.. EPSS estimates a 8.42% chance of exploitation in the next 30 days.
Description
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Atom C | c2308 |
| Intel | Atom C | c2316 |
| Intel | Atom C | c2338 |
| Intel | Atom C | c2350 |
| Intel | Atom C | c2358 |
| Intel | Atom C | c2508 |
| Intel | Atom C | c2516 |
| Intel | Atom C | c2518 |
| Intel | Atom C | c2530 |
| Intel | Atom C | c2538 |
| Intel | Atom C | c2550 |
| Intel | Atom C | c2558 |
| Intel | Atom C | c2718 |
| Intel | Atom C | c2730 |
| Intel | Atom C | c2738 |
| Intel | Atom C | c2750 |
| Intel | Atom C | c2758 |
| Intel | Atom C | c3308 |
| Intel | Atom C | c3338 |
| Intel | Atom C | c3508 |
| Intel | Atom C | c3538 |
| Intel | Atom C | c3558 |
| Intel | Atom C | c3708 |
| Intel | Atom C | c3750 |
| Intel | Atom C | c3758 |
| Intel | Atom C | c3808 |
| Intel | Atom C | c3830 |
| Intel | Atom C | c3850 |
| Intel | Atom C | c3858 |
| Intel | Atom C | c3950 |
| Intel | Atom C | c3955 |
| Intel | Atom C | c3958 |
| Intel | Atom E | e3805 |
| Intel | Atom E | e3815 |
| Intel | Atom E | e3825 |
| Intel | Atom E | e3826 |
| Intel | Atom E | e3827 |
| Intel | Atom E | e3845 |
| Intel | Atom X3 | c3130 |
| Intel | Atom X3 | c3200rk |
| Intel | Atom X3 | c3205rk |
| Intel | Atom X3 | c3230rk |
| Intel | Atom X3 | c3235rk |
| Intel | Atom X3 | c3265rk |
| Intel | Atom X3 | c3295rk |
| Intel | Atom X3 | c3405 |
| Intel | Atom X3 | c3445 |
| Intel | Atom Z | z2420 |
| Intel | Atom Z | z2460 |
| Intel | Atom Z | z2480 |
Showing 50 of 1092 affected configurations. See NVD for the full list.
References
- https://access.redhat.com/errata/RHSA-2018:2384Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2390Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2395Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1946Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0174Third Party Advisory
- https://cdrdv2.intel.com/v1/dl/getContent/685359Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180823-0001/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2384Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2390Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2395Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1946Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0174Third Party Advisory
- https://cdrdv2.intel.com/v1/dl/getContent/685359Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180823-0001/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-3693?
How severe is CVE-2018-3693?
How do I fix CVE-2018-3693?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-3687Unquoted service paths in Intel Quartus II Programmer and To…
- CVE-2018-3688Unquoted service paths in Intel Quartus Prime Programmer and…
- CVE-2018-3689AESM daemon in Intel Software Guard Extensions Platform Soft…5.5
- CVE-2018-3690Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-3691Some implementations in Intel Integrated Performance Primiti…
- CVE-2018-3692Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-3694Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-3695Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-3696Authentication bypass in the Intel RAID Web Console 3 for Wi…
- CVE-2018-3697Improper directory permissions in the installer for the Inte…
- CVE-2018-3698Improper file permissions in the installer for the Intel Rea…
- CVE-2018-3699Cross-site scripting in the Intel RAID Web Console v3 for Wi…
Are you affected by CVE-2018-3693?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
