CVE-2018-3640

MEDIUM

Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.

CVSS v3.1 Score

5.6
MEDIUM
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Complexity
HIGH
Privileges
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE
Published: 5/22/2018Modified: 6/17/2026

Related Intelligence (1)

References (44)

http://support.lenovo.com/us/en/solutions/LEN-22133Third Party Advisoryhttp://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.htmlThird Party Advisoryhttp://www.securityfocus.com/bid/104228Third Party AdvisoryVDB Entryhttp://www.securitytracker.com/id/1040949Third Party AdvisoryVDB Entryhttp://www.securitytracker.com/id/1042004https://cert-portal.siemens.com/productcert/pdf/ssa-268644.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityVendor Advisoryhttps://lists.debian.org/debian-lts-announce/2018/07/msg00038.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV180013PatchThird Party Advisoryhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0005https://security.netapp.com/advisory/ntap-20180521-0001/Third Party Advisoryhttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03850en_usThird Party Advisoryhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180521-cpusidechannelThird Party Advisoryhttps://usn.ubuntu.com/3756-1/https://www.debian.org/security/2018/dsa-4273https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.htmlVendor Advisoryhttps://www.kb.cert.org/vuls/id/180049Third Party AdvisoryUS Government Resourcehttps://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0006https://www.synology.com/support/security/Synology_SA_18_23Third Party Advisoryhttps://www.us-cert.gov/ncas/alerts/TA18-141AThird Party AdvisoryUS Government Resourcehttp://support.lenovo.com/us/en/solutions/LEN-22133Third Party Advisoryhttp://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.htmlThird Party Advisoryhttp://www.securityfocus.com/bid/104228Third Party AdvisoryVDB Entryhttp://www.securitytracker.com/id/1040949Third Party AdvisoryVDB Entryhttp://www.securitytracker.com/id/1042004https://cert-portal.siemens.com/productcert/pdf/ssa-268644.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityVendor Advisoryhttps://lists.debian.org/debian-lts-announce/2018/07/msg00038.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV180013PatchThird Party Advisoryhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0005https://security.netapp.com/advisory/ntap-20180521-0001/Third Party Advisoryhttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03850en_usThird Party Advisoryhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180521-cpusidechannelThird Party Advisoryhttps://usn.ubuntu.com/3756-1/https://www.debian.org/security/2018/dsa-4273https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.htmlVendor Advisoryhttps://www.kb.cert.org/vuls/id/180049Third Party AdvisoryUS Government Resourcehttps://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0006https://www.synology.com/support/security/Synology_SA_18_23Third Party Advisoryhttps://www.us-cert.gov/ncas/alerts/TA18-141AThird Party AdvisoryUS Government Resource