CVE-2017-5715
57Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.6epss 74%
from disclosure to weapon0 days
Published on NVDJan 4
1st PoCJan 3
exploitation probability
74%top 1% of all CVEs
observed exploitation
nono source reports it
9 public exploit(s)
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected products
Intel Corporation · Microprocessors with Speculative Executionpublic PoCs found — 9
exploitdbwww.exploit-db.com/exploits/43427unverifiedgithubgithub.com/opsxcq/exploit-cve-2017-5715★ 54githubgithub.com/mathse/meltdown-spectre-bios-list★ 17githubgithub.com/GregAskew/SpeculativeExecutionAssessment★ 0githubgithub.com/GalloLuigi/Analisi-CVE-2017-5715★ 0githubgithub.com/iamshivambhatt/Hardware-Vulnerability-with-Proof-of-Concept-★ 0cve_referencewww.exploit-db.com/exploits/43427/unverifiedcve_referencepacketstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.htmlunverifiedcve_referencepacketstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html