CVE-2022-40982

MEDIUMCVSS 6.5/10EPSS 3.91%

Last modified

CVE-2022-40982 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.. EPSS estimates a 3.91% chance of exploitation in the next 30 days.

Description

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS Probability
3.91%

89.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RedhatEnterprise Linux6.0
RedhatEnterprise Linux7.0
RedhatEnterprise Linux8.0
RedhatEnterprise Linux9.0
XenXenAll versions
IntelMicrocode< 20230808
IntelXeon E-2314 FirmwareAll versions
IntelXeon E-2324g FirmwareAll versions
IntelXeon E-2334 FirmwareAll versions
IntelXeon E-2374g FirmwareAll versions
IntelXeon E-2336 FirmwareAll versions
IntelXeon E-2356g FirmwareAll versions
IntelXeon E-2386g FirmwareAll versions
IntelXeon E-2378 FirmwareAll versions
IntelXeon E-2378g FirmwareAll versions
IntelXeon E-2388g FirmwareAll versions
IntelXeon W-1350 FirmwareAll versions
IntelXeon W-1350p FirmwareAll versions
IntelXeon W-1370 FirmwareAll versions
IntelXeon W-1370p FirmwareAll versions
IntelXeon W-1390t FirmwareAll versions
IntelXeon W-1390 FirmwareAll versions
IntelXeon W-1390p FirmwareAll versions
IntelCore I9-11900t FirmwareAll versions
IntelCore I9-11900f FirmwareAll versions
IntelCore I9-11900 FirmwareAll versions
IntelCore I9-11900kf FirmwareAll versions
IntelCore I9-11900k FirmwareAll versions
IntelCore I7-11700t FirmwareAll versions
IntelCore I7-11700f FirmwareAll versions
IntelCore I7-11700 FirmwareAll versions
IntelCore I7-11700kf FirmwareAll versions
IntelCore I7-11700k FirmwareAll versions
IntelCore I5-11400t FirmwareAll versions
IntelCore I5-11400f FirmwareAll versions
IntelCore I5-11400 FirmwareAll versions
IntelCore I5-11500t FirmwareAll versions
IntelCore I5-11500 FirmwareAll versions
IntelCore I5-11600t FirmwareAll versions
IntelCore I5-11600 FirmwareAll versions
IntelCore I5-11600kf FirmwareAll versions
IntelCore I5-11600k FirmwareAll versions
IntelCeleron G5900t FirmwareAll versions
IntelCeleron G5920 FirmwareAll versions
IntelCeleron G5900 FirmwareAll versions
IntelCeleron G5925 FirmwareAll versions
IntelCeleron G5905t FirmwareAll versions
IntelCeleron G5905 FirmwareAll versions
IntelPentium Gold G6500t FirmwareAll versions
IntelPentium Gold G6600 FirmwareAll versions

Showing 50 of 539 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-40982?
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
How severe is CVE-2022-40982?
CVE-2022-40982 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 3.91% probability of exploitation in the next 30 days.
How do I fix CVE-2022-40982?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-40982?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST