Vulnerability Description
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Atom C | c2308 |
| Intel | Atom E | e3805 |
| Intel | Atom X3 | c3130 |
| Intel | Atom Z | z2420 |
| Intel | Celeron J | j1750 |
| Intel | Celeron N | n2805 |
| Intel | Core I3 | 330e |
| Intel | Core I5 | 430m |
| Intel | Core I7 | 7y75 |
| Intel | Core M | 5y10 |
| Intel | Core M3 | 6y30 |
| Intel | Core M5 | 6y54 |
| Intel | Core M7 | 6y75 |
| Intel | Pentium J | j2850 |
| Intel | Pentium N | n3510 |
| Intel | Xeon | e5502 |
| Intel | Xeon Bronze 3104 | - |
| Intel | Xeon Bronze 3106 | - |
| Intel | Xeon E-1105C | - |
| Intel | Xeon E3 | 1505m_v6 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html
- http://nvidia.custhelp.com/app/answers/detail/a_id/4609Third Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4611
- http://nvidia.custhelp.com/app/answers/detail/a_id/4613
- http://nvidia.custhelp.com/app/answers/detail/a_id/4614
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt
- http://www.kb.cert.org/vuls/id/584653Third Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/102378
- http://www.securityfocus.com/bid/106128
- http://www.securitytracker.com/id/1040071Third Party AdvisoryVDB Entry
FAQ
What is CVE-2017-5754?
CVE-2017-5754 is a vulnerability with a CVSS score of 5.6 (MEDIUM). Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel an...
How severe is CVE-2017-5754?
CVE-2017-5754 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-5754?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Atom C, Intel Atom E, Intel Atom X3, Intel Atom Z, Intel Celeron J.