CVE-2022-48251
Last modified
CVE-2022-48251 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not directly caused by or related to the Arm architecture."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arm | Cortex-A53 Firmware | All versions |
| Arm | Cortex-A55 Firmware | All versions |
| Arm | Cortex-A57 Firmware | All versions |
| Arm | Cortex-A72 Firmware | All versions |
| Arm | Cortex-A73 Firmware | All versions |
| Arm | Cortex-A75 Firmware | All versions |
| Arm | Cortex-A76 Firmware | All versions |
| Arm | Cortex-A76ae Firmware | All versions |
| Arm | Cortex-A77 Firmware | All versions |
| Arm | Cortex-A78 Firmware | All versions |
References
- https://eprint.iacr.org/2022/230Technical Description, Third Party Advisory
- https://eshard.com/posts/sca-attacks-on-armv8Exploit, Third Party Advisory
- https://eprint.iacr.org/2022/230Technical Description, Third Party Advisory
- https://eshard.com/posts/sca-attacks-on-armv8Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-48251?
How severe is CVE-2022-48251?
How do I fix CVE-2022-48251?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-48246In audio service, there is a possible missing permission che…7.8
- CVE-2022-48247In audio service, there is a possible missing permission che…7.8
- CVE-2022-48248In audio service, there is a possible missing permission che…7.8
- CVE-2022-48249In audio service, there is a possible missing permission che…7.8
- CVE-2022-4825The WP-ShowHide WordPress plugin before 1.05 does not valida…5.4
- CVE-2022-48250In audio service, there is a possible missing permission che…7.8
- CVE-2022-48252The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert all…9.8
- CVE-2022-48253nhttpd in Nostromo before 2.1 is vulnerable to a path traver…9.8
- CVE-2022-48254There is a data processing error vulnerability in Leia-B29 2…4.6
- CVE-2022-48255There is a system command injection vulnerability in BiSheng…9.8
- CVE-2022-48256Technitium DNS Server before 10.0 allows a self-CNAME denial…7.5
- CVE-2022-48257In Eternal Terminal 6.2.1, etserver and etclient have predic…5.3
Are you affected by CVE-2022-48251?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
