CVE-2018-3620

MEDIUM

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.

CVSS v3.1 Score

5.6
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Complexity
HIGH
Privileges
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE
Published: 8/14/2018Modified: 6/17/2026

Related Intelligence (1)

References (106)

http://support.lenovo.com/us/en/solutions/LEN-24163Third Party Advisoryhttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180815-01-cpu-enThird Party Advisoryhttp://www.securityfocus.com/bid/105080Third Party AdvisoryVDB Entryhttp://www.securitytracker.com/id/1041451Third Party AdvisoryVDB Entryhttp://www.vmware.com/security/advisories/VMSA-2018-0021.htmlThird Party Advisoryhttp://xenbits.xen.org/xsa/advisory-273.htmlThird Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2384Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2387Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2388Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2389Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2390Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2391Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2392Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2393Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2394Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2395Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2396Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2402Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2403Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2404Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2602https://access.redhat.com/errata/RHSA-2018:2603https://cert-portal.siemens.com/productcert/pdf/ssa-254686.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://foreshadowattack.eu/Technical DescriptionThird Party Advisoryhttps://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/08/msg00029.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V4UWGORQWCENCIF2BHWUEF2ODBV75QS2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XRFKQWYV2H4BV75CUNGCGE5TNVQCLBGZ/https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180018https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0009Third Party Advisoryhttps://security.FreeBSD.org/advisories/FreeBSD-SA-18:09.l1tf.ascThird Party Advisoryhttps://security.gentoo.org/glsa/201810-06https://security.netapp.com/advisory/ntap-20180815-0001/Third Party Advisoryhttps://software.intel.com/security-software-guidance/software-guidance/l1-terminal-faultMitigationVendor Advisoryhttps://support.f5.com/csp/article/K95275140Third Party Advisoryhttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03874en_usThird Party Advisoryhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180814-cpusidechannelThird Party Advisoryhttps://usn.ubuntu.com/3740-1/Third Party Advisoryhttps://usn.ubuntu.com/3740-2/Third Party Advisoryhttps://usn.ubuntu.com/3741-1/Third Party Advisoryhttps://usn.ubuntu.com/3741-2/https://usn.ubuntu.com/3742-1/Third Party Advisoryhttps://usn.ubuntu.com/3742-2/Third Party Advisoryhttps://usn.ubuntu.com/3823-1/https://www.debian.org/security/2018/dsa-4274https://www.debian.org/security/2018/dsa-4279https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.htmlVendor Advisoryhttps://www.kb.cert.org/vuls/id/982149https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.synology.com/support/security/Synology_SA_18_45Third Party Advisoryhttp://support.lenovo.com/us/en/solutions/LEN-24163Third Party Advisoryhttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180815-01-cpu-enThird Party Advisoryhttp://www.securityfocus.com/bid/105080Third Party AdvisoryVDB Entryhttp://www.securitytracker.com/id/1041451Third Party AdvisoryVDB Entryhttp://www.vmware.com/security/advisories/VMSA-2018-0021.htmlThird Party Advisoryhttp://xenbits.xen.org/xsa/advisory-273.htmlThird Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2384Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2387Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2388Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2389Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2390Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2391Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2392Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2393Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2394Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2395Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2396Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2402Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2403Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2404Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2018:2602https://access.redhat.com/errata/RHSA-2018:2603https://cert-portal.siemens.com/productcert/pdf/ssa-254686.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://foreshadowattack.eu/Technical DescriptionThird Party Advisoryhttps://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/08/msg00029.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V4UWGORQWCENCIF2BHWUEF2ODBV75QS2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XRFKQWYV2H4BV75CUNGCGE5TNVQCLBGZ/https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180018https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0009Third Party Advisoryhttps://security.FreeBSD.org/advisories/FreeBSD-SA-18:09.l1tf.ascThird Party Advisoryhttps://security.gentoo.org/glsa/201810-06https://security.netapp.com/advisory/ntap-20180815-0001/Third Party Advisoryhttps://software.intel.com/security-software-guidance/software-guidance/l1-terminal-faultMitigationVendor Advisoryhttps://support.f5.com/csp/article/K95275140Third Party Advisoryhttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03874en_usThird Party Advisoryhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180814-cpusidechannelThird Party Advisoryhttps://usn.ubuntu.com/3740-1/Third Party Advisoryhttps://usn.ubuntu.com/3740-2/Third Party Advisoryhttps://usn.ubuntu.com/3741-1/Third Party Advisoryhttps://usn.ubuntu.com/3741-2/https://usn.ubuntu.com/3742-1/Third Party Advisoryhttps://usn.ubuntu.com/3742-2/Third Party Advisoryhttps://usn.ubuntu.com/3823-1/https://www.debian.org/security/2018/dsa-4274https://www.debian.org/security/2018/dsa-4279https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.htmlVendor Advisoryhttps://www.kb.cert.org/vuls/id/982149https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.synology.com/support/security/Synology_SA_18_45Third Party Advisory