peter bassill · operator
$ cve CVE-2018-3639 JSON

CVE-2018-3639 EXPLOIT

5.5
MEDIUM · CVSS 3.1 · EPSS 60.6% (pctl 99)

Patch early

A public exploit exists.

Description

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

Scoring

CVSS5.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS60.63% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-203
On CISA KEVno
Public exploityes
Published2018-05-22
Last modified2026-06-17

Affected (40)

VendorProduct
intelatom c
intelatom e
intelatom x5-e3930
intelatom x5-e3940
intelatom x7-e3950
intelatom z
intelceleron j
intelceleron n
intelcore i3
intelcore i5
intelcore i7
intelcore m
intelpentium
intelpentium j
intelpentium silver
intelxeon e-1105c
intelxeon e3
intelxeon e3 1105c v2
intelxeon e3 1125c v2
intelxeon e3 1220 v2
intelxeon e3 1220 v3
intelxeon e3 1220 v5
intelxeon e3 1220 v6
intelxeon e3 12201
intelxeon e3 12201 v2
intelxeon e3 1220l v3
intelxeon e3 1225
intelxeon e3 1225 v2
intelxeon e3 1225 v3
intelxeon e3 1225 v5
intelxeon e3 1225 v6
intelxeon e3 1226 v3
intelxeon e3 1230
intelxeon e3 1230 v2
intelxeon e3 1230 v3
intelxeon e3 1230 v5
intelxeon e3 1230 v6
intelxeon e3 1230l v3
intelxeon e3 1231 v3
intelxeon e3 1235

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD