CVE-2022-40982
Last modified
CVE-2022-40982 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.. EPSS estimates a 3.91% chance of exploitation in the next 30 days.
Description
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux | 6.0 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux | 9.0 |
| Xen | Xen | All versions |
| Intel | Microcode | < 20230808 |
| Intel | Xeon E-2314 Firmware | All versions |
| Intel | Xeon E-2324g Firmware | All versions |
| Intel | Xeon E-2334 Firmware | All versions |
| Intel | Xeon E-2374g Firmware | All versions |
| Intel | Xeon E-2336 Firmware | All versions |
| Intel | Xeon E-2356g Firmware | All versions |
| Intel | Xeon E-2386g Firmware | All versions |
| Intel | Xeon E-2378 Firmware | All versions |
| Intel | Xeon E-2378g Firmware | All versions |
| Intel | Xeon E-2388g Firmware | All versions |
| Intel | Xeon W-1350 Firmware | All versions |
| Intel | Xeon W-1350p Firmware | All versions |
| Intel | Xeon W-1370 Firmware | All versions |
| Intel | Xeon W-1370p Firmware | All versions |
| Intel | Xeon W-1390t Firmware | All versions |
| Intel | Xeon W-1390 Firmware | All versions |
| Intel | Xeon W-1390p Firmware | All versions |
| Intel | Core I9-11900t Firmware | All versions |
| Intel | Core I9-11900f Firmware | All versions |
| Intel | Core I9-11900 Firmware | All versions |
| Intel | Core I9-11900kf Firmware | All versions |
| Intel | Core I9-11900k Firmware | All versions |
| Intel | Core I7-11700t Firmware | All versions |
| Intel | Core I7-11700f Firmware | All versions |
| Intel | Core I7-11700 Firmware | All versions |
| Intel | Core I7-11700kf Firmware | All versions |
| Intel | Core I7-11700k Firmware | All versions |
| Intel | Core I5-11400t Firmware | All versions |
| Intel | Core I5-11400f Firmware | All versions |
| Intel | Core I5-11400 Firmware | All versions |
| Intel | Core I5-11500t Firmware | All versions |
| Intel | Core I5-11500 Firmware | All versions |
| Intel | Core I5-11600t Firmware | All versions |
| Intel | Core I5-11600 Firmware | All versions |
| Intel | Core I5-11600kf Firmware | All versions |
| Intel | Core I5-11600k Firmware | All versions |
| Intel | Celeron G5900t Firmware | All versions |
| Intel | Celeron G5920 Firmware | All versions |
| Intel | Celeron G5900 Firmware | All versions |
| Intel | Celeron G5925 Firmware | All versions |
| Intel | Celeron G5905t Firmware | All versions |
| Intel | Celeron G5905 Firmware | All versions |
| Intel | Pentium Gold G6500t Firmware | All versions |
| Intel | Pentium Gold G6600 Firmware | All versions |
Showing 50 of 539 affected configurations. See NVD for the full list.
References
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.htmlExploit, Mitigation, Vendor Advisory
- https://access.redhat.com/solutions/7027704Third Party Advisory
- https://aws.amazon.com/security/security-bulletins/AWS-2023-007/Third Party Advisory
- https://downfall.pageExploit, Technical Description, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00013.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230811-0001/Third Party Advisory
- https://www.debian.org/security/2023/dsa-5474Mailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5475Mailing List, Third Party Advisory
- https://xenbits.xen.org/xsa/advisory-435.htmlMitigation, Third Party Advisory
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.htmlExploit, Mitigation, Vendor Advisory
- https://access.redhat.com/solutions/7027704Third Party Advisory
- https://aws.amazon.com/security/security-bulletins/AWS-2023-007/Third Party Advisory
- https://downfall.pageExploit, Technical Description, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00013.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230811-0001/Third Party Advisory
- https://www.debian.org/security/2023/dsa-5474Mailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5475Mailing List, Third Party Advisory
- https://xenbits.xen.org/xsa/advisory-435.htmlMitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-40982?
How severe is CVE-2022-40982?
How do I fix CVE-2022-40982?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-40977A path traversal vulnerability was discovered in Pilz PASvis…7.5
- CVE-2022-40978The installer of JetBrains IntelliJ IDEA before 2022.2.2 was…7.8
- CVE-2022-40979In JetBrains TeamCity before 2022.04.4 environmental variabl…5.3
- CVE-2022-4098Multiple Wiesemann&Theis products of the ComServer Series ar…8
- CVE-2022-40980A potential unathenticated file deletion vulnerabilty on Tre…9.1
- CVE-2022-40981All versions of ETIC Telecom Remote Access Server (RAS) 4.5.…10
- CVE-2022-40983An integer overflow vulnerability exists in the QML QtScript…8.8
- CVE-2022-40984Stack-based buffer overflow in WTViewerE series WTViewerE 76…9.8
- CVE-2022-40985Several stack-based buffer overflow vulnerabilities exist in…9.8
- CVE-2022-40986Several stack-based buffer overflow vulnerabilities exist in…9.8
- CVE-2022-40987Several stack-based buffer overflow vulnerabilities exist in…9.8
- CVE-2022-40988Several stack-based buffer overflow vulnerabilities exist in…9.8
Are you affected by CVE-2022-40982?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
