HIGH · 7.5

CVE-2022-48251

The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel...

Vulnerability Description

The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not directly caused by or related to the Arm architecture."

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ArmCortex-A53 Firmware-
ArmCortex-A53-
ArmCortex-A55 Firmware-
ArmCortex-A55-
ArmCortex-A57 Firmware-
ArmCortex-A57-
ArmCortex-A72 Firmware-
ArmCortex-A72-
ArmCortex-A73 Firmware-
ArmCortex-A73-
ArmCortex-A75 Firmware-
ArmCortex-A75-
ArmCortex-A76 Firmware-
ArmCortex-A76-
ArmCortex-A76Ae Firmware-
ArmCortex-A76Ae-
ArmCortex-A77 Firmware-
ArmCortex-A77-
ArmCortex-A78 Firmware-
ArmCortex-A78-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-48251?

CVE-2022-48251 is a vulnerability with a CVSS score of 7.5 (HIGH). The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel...

How severe is CVE-2022-48251?

CVE-2022-48251 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-48251?

Check the references section above for vendor advisories and patch information. Affected products include: Arm Cortex-A53 Firmware, Arm Cortex-A53, Arm Cortex-A55 Firmware, Arm Cortex-A55, Arm Cortex-A57 Firmware.