CVE-2022-0001

MEDIUMCVSS 6.5/10EPSS 0.51%

Last modified

CVE-2022-0001 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.

Description

Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS Probability
0.51%

39.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IntelAtom P5921bAll versions
IntelAtom P5931bAll versions
IntelAtom P5942bAll versions
IntelAtom P5962bAll versions
IntelAtom X6200feAll versions
IntelAtom X6211eAll versions
IntelAtom X6212reAll versions
IntelAtom X6413eAll versions
IntelAtom X6425eAll versions
IntelAtom X6425reAll versions
IntelAtom X6427feAll versions
IntelCeleron 5305uAll versions
IntelCeleron 6305All versions
IntelCeleron 6305eAll versions
IntelCeleron 6600heAll versions
IntelCeleron G5205uAll versions
IntelCeleron G5305uAll versions
IntelCeleron G5900All versions
IntelCeleron G5900tAll versions
IntelCeleron G5905All versions
IntelCeleron G5905tAll versions
IntelCeleron G5920All versions
IntelCeleron G5925All versions
IntelCeleron G6900All versions
IntelCeleron G6900tAll versions
IntelCeleron J4005All versions
IntelCeleron J4025All versions
IntelCeleron J4105All versions
IntelCeleron J4125All versions
IntelCeleron J6413All versions
IntelCeleron N4000All versions
IntelCeleron N4020All versions
IntelCeleron N4100All versions
IntelCeleron N4120All versions
IntelCeleron N4500All versions
IntelCeleron N4504All versions
IntelCeleron N5100All versions
IntelCeleron N5105All versions
IntelCeleron N6211All versions
IntelCore I3-1000g1All versions
IntelCore I3-1000g4All versions
IntelCore I3-1005g1All versions
IntelCore I3-10100All versions
IntelCore I3-10100fAll versions
IntelCore I3-10100tAll versions
IntelCore I3-10100teAll versions
IntelCore I3-10105All versions
IntelCore I3-10105fAll versions
IntelCore I3-10105tAll versions
IntelCore I3-10110uAll versions

Showing 50 of 458 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-0001?
Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
How severe is CVE-2022-0001?
CVE-2022-0001 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.51% probability of exploitation in the next 30 days.
How do I fix CVE-2022-0001?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-0001?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST