CVE-2018-3615

HIGH

Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.

CVSS v3.1 Score

7.3
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Attack Vector
LOCAL
Complexity
LOW
Privileges
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
NONE
Published: 8/14/2018Modified: 6/17/2026

Related Intelligence (1)

References (34)

http://support.lenovo.com/us/en/solutions/LEN-24163Third Party Advisoryhttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180815-01-cpu-enThird Party Advisoryhttp://www.securityfocus.com/bid/105080Third Party AdvisoryVDB Entryhttp://www.securitytracker.com/id/1041451Third Party AdvisoryVDB Entryhttps://cert-portal.siemens.com/productcert/pdf/ssa-254686.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://foreshadowattack.eu/Technical DescriptionThird Party Advisoryhttps://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0008Third Party Advisoryhttps://security.netapp.com/advisory/ntap-20180815-0001/Third Party Advisoryhttps://software.intel.com/security-software-guidance/software-guidance/l1-terminal-faultMitigationVendor Advisoryhttps://support.f5.com/csp/article/K35558453Third Party Advisoryhttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03874en_usThird Party Advisoryhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180814-cpusidechannelThird Party Advisoryhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.htmlVendor Advisoryhttps://www.kb.cert.org/vuls/id/982149Third Party Advisoryhttps://www.synology.com/support/security/Synology_SA_18_45Third Party Advisoryhttp://support.lenovo.com/us/en/solutions/LEN-24163Third Party Advisoryhttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180815-01-cpu-enThird Party Advisoryhttp://www.securityfocus.com/bid/105080Third Party AdvisoryVDB Entryhttp://www.securitytracker.com/id/1041451Third Party AdvisoryVDB Entryhttps://cert-portal.siemens.com/productcert/pdf/ssa-254686.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://foreshadowattack.eu/Technical DescriptionThird Party Advisoryhttps://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0008Third Party Advisoryhttps://security.netapp.com/advisory/ntap-20180815-0001/Third Party Advisoryhttps://software.intel.com/security-software-guidance/software-guidance/l1-terminal-faultMitigationVendor Advisoryhttps://support.f5.com/csp/article/K35558453Third Party Advisoryhttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03874en_usThird Party Advisoryhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180814-cpusidechannelThird Party Advisoryhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.htmlVendor Advisoryhttps://www.kb.cert.org/vuls/id/982149Third Party Advisoryhttps://www.synology.com/support/security/Synology_SA_18_45Third Party Advisory