Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-5715

74
FAUCET Score

CVE-2017-5715, widely identified as the Spectre side-channel vulnerability, affects microprocessors from major vendors including Intel and Arm by exploiting speculative execution and indirect branch prediction to leak sensitive data. Despite a Medium CVSS score of 5.6 due to the requirement for local access and high attack complexity, the flaw presents a critical risk of unauthorized information disclosure across security boundaries. Proof-of-concept code is available on ExploitDB, and the vulnerability maintains an exceptionally high EPSS score and significant community attention, necessitating reliance on OS-level mitigations such as Retpoline.

Impacted Technologies

VendorProductVersion(s)CPE
c2308CPE matchmatch criteria
cpe:2.3:h:intel:atom_c:c2308:*:*:*:*:*:*:*
c2316CPE matchmatch criteria
cpe:2.3:h:intel:atom_c:c2316:*:*:*:*:*:*:*
c2338CPE matchmatch criteria
cpe:2.3:h:intel:atom_c:c2338:*:*:*:*:*:*:*
c2350CPE matchmatch criteria
cpe:2.3:h:intel:atom_c:c2350:*:*:*:*:*:*:*
c2358CPE matchmatch criteria
cpe:2.3:h:intel:atom_c:c2358:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.6MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.1
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
74.21%
Probability of exploitation in next 30 days
EPSS Percentile
99.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
ExploitDB: EDB-43427 · Jan 3, 2018
This CVE's current EPSS score of 0.7421 is in the 100th percentile among its peer group of 1,296 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (52)

coollabspatch availablevia llm_extracted
libreofficepatch availablevia llm_extracted
Fixed in: OpenVPN Access Server bundled Clients Package v14
View patch
microsoftpatch availablevia nvd_reference
View patch
openvpnpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Extended Update SupportFixed in: kernel-0:3.10.0-693.25.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.2 Advanced Update SupportFixed in: kernel-0:2.6.32-220.76.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.4 Advanced Update SupportFixed in: kernel-0:2.6.32-358.84.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.5 Advanced Update SupportFixed in: kernel-0:2.6.32-431.85.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.6 Advanced Update SupportFixed in: kernel-0:2.6.32-504.64.4.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.6 Telco Extended Update SupportFixed in: kernel-0:2.6.32-504.64.4.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.7 Extended Update SupportFixed in: kernel-0:2.6.32-573.55.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-693.11.1.rt56.639.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: dracut-0:033-502.el7_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: qemu-kvm-ma-10:2.10.0-21.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: microcode_ctl-2:2.1-29.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: libvirt-0:3.9.0-14.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: linux-firmware-0:20180220-62.git6d51311.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: qemu-kvm-10:1.5.3-141.el7_4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-862.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt-0:4.14.0-49.8.1.el7a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Advanced Update SupportFixed in: kernel-0:3.10.0-327.66.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Telco Extended Update SupportFixed in: kernel-0:3.10.0-327.66.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-327.66.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Extended Update SupportFixed in: qemu-kvm-10:1.5.3-126.el7_3.13
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Extended Update SupportFixed in: kernel-0:3.10.0-514.48.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-693.11.1.rt56.606.el6rt
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-7 ELSFixed in: qemu-kvm-rhev-10:2.6.0-28.el7_3.15
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.9 Long LifeFixed in: kernel-0:2.6.18-348.39.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5 Extended Lifecycle SupportFixed in: kernel-0:2.6.18-430.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-696.28.1.el6
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Virtualization 3Fixed in: vdsm
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 10 (Newton)Fixed in: qemu-kvm-rhev
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 11 (Ocata)Fixed in: qemu-kvm-rhev
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 12 (Pike)Fixed in: qemu-kvm-rhev
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 8 (Liberty)Fixed in: qemu-kvm-rhev
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 9 (Mitaka)Fixed in: qemu-kvm-rhev
redhatno patchvia redhat_api
Product: Red Hat Virtualization 4Fixed in: ovirt-guest-agent-docker
redhatno patchvia redhat_api
Product: Red Hat Virtualization 4Fixed in: redhat-virtualization-host
redhatno patchvia redhat_api
Product: Red Hat Virtualization 4Fixed in: rhevm-appliance
redhatno patchvia redhat_api
Product: Red Hat Virtualization 4Fixed in: rhevm-setup-plugins
redhatno patchvia redhat_api
Product: Red Hat Virtualization 4Fixed in: vdsm
redhatno patchvia redhat_api
Product: Red Hat Enterprise Virtualization 3Fixed in: rhev-hypervisor-ng
redhatno patchvia redhat_api
Product: Red Hat Enterprise Virtualization 3Fixed in: rhevm-setup-plugins
redhatno patchvia redhat_api
Product: Red Hat Enterprise Virtualization 3Fixed in: rhev-hypervisor
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)Fixed in: qemu-kvm-rhev
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: microcode_ctl
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: libvirt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: microcode_ctl
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: qemu-kvm
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: qemu-kvm-rhev
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: qemu-kvm
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 6 (Juno)Fixed in: qemu-kvm-rhev

Vendor Advisories (4)

coollabsllm-coollabs-861bcc8082959b4eCRITICAL

Processor Vulnerabilities (Spectre and Meltdown)

Apr 19, 2018
redhatCVE-2017-5715Important

hw: cpu: speculative execution branch target injection

Jan 3, 2018
openvpnllm-openvpn-1db827e286909e83

Spectre and Meltdown CPU Vulnerabilities Affecting Underlying Operating Systems

libreofficellm-libreoffice-ff72b84b661c0888

Spectre and Meltdown CPU Vulnerabilities

References

lists.opensuse.org / opensuse-security-announce/2018-01/msg00002.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2018-01/msg00003.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2018-01/msg00004.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2018-01/msg00005.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2018-01/msg00006.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2018-01/msg00007.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2018-01/msg00008.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2018-01/msg00009.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2018-01/msg00012.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2018-01/msg00013.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2018-01/msg00014.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2018-01/msg00016.html
Broken Link
nvidia.custhelp.com / app/answers/detail/a_id/4609
Third Party Advisory
nvidia.custhelp.com / app/answers/detail/a_id/4611
Third Party Advisory
nvidia.custhelp.com / app/answers/detail/a_id/4613
Third Party Advisory
nvidia.custhelp.com / app/answers/detail/a_id/4614
Third Party Advisory
packetstormsecurity.com / files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.html
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2018:0292
Third Party Advisory
access.redhat.com / security/vulnerabilities/speculativeexecution
Third Party Advisory
aws.amazon.com / de/security/security-bulletins/AWS-2018-013
Third Party Advisory
blog.mozilla.org / security/2018/01/03/mitigations-landing-new-class-timing-attack
Third Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-608355.pdf
Third Party Advisory
cert.vde.com / en-us/advisories/vde-2018-002
Third Party Advisory
cert.vde.com / en-us/advisories/vde-2018-003
Third Party Advisory
developer.arm.com / support/arm-security-updates/speculative-processor-vulnerability
Third Party Advisory
googleprojectzero.blogspot.com / 2018/01/reading-privileged-memory-with-side.html
Third Party Advisory
help.ecostruxureit.com / display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes
Third Party Advisory
lists.debian.org / debian-lts-announce/2018/05/msg00000.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2018/07/msg00015.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2018/07/msg00016.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2018/09/msg00007.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2018/09/msg00017.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/03/msg00025.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2021/08/msg00019.html
portal.msrc.microsoft.com / en-US/security-guidance/advisory/ADV180002
PatchThird Party AdvisoryVendor Advisory
seclists.org / bugtraq/2019/Jun/36
Issue TrackingMailing ListThird Party Advisory
seclists.org / bugtraq/2019/Nov/16
Issue TrackingMailing ListThird Party Advisory
security-center.intel.com / advisory.aspx
Vendor Advisory
security.freebsd.org / advisories/FreeBSD-SA-18:03.speculative_execution.asc
Third Party Advisory
security.freebsd.org / advisories/FreeBSD-SA-19:26.mcu.asc
Third Party Advisory
security.gentoo.org / glsa/201810-06
Third Party Advisory
security.googleblog.com / 2018/01/todays-cpu-vulnerability-what-you-need.html
Third Party Advisory
security.netapp.com / advisory/ntap-20180104-0001
Third Party Advisory
security.paloaltonetworks.com / CVE-2017-5715
Third Party Advisory
spectreattack.com
Third Party Advisory
support.citrix.com / article/CTX231399
Third Party Advisory
support.f5.com / csp/article/K91229003
Third Party Advisory
support.hpe.com / hpsc/doc/public/display
Third Party Advisory
support.hpe.com / hpsc/doc/public/display
Third Party Advisory
support.lenovo.com / us/en/solutions/LEN-18282
Third Party Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannel
Third Party Advisory
usn.ubuntu.com / 3531-1
Third Party Advisory
usn.ubuntu.com / 3531-3
Third Party Advisory
usn.ubuntu.com / 3540-2
Third Party Advisory
usn.ubuntu.com / 3541-2
Third Party Advisory
usn.ubuntu.com / 3542-2
Third Party Advisory
usn.ubuntu.com / 3549-1
Third Party Advisory
usn.ubuntu.com / 3560-1
Third Party Advisory
usn.ubuntu.com / 3561-1
Third Party Advisory
usn.ubuntu.com / 3580-1
Third Party Advisory
usn.ubuntu.com / 3581-1
Third Party Advisory
usn.ubuntu.com / 3581-2
Third Party Advisory
usn.ubuntu.com / 3582-1
Third Party Advisory
usn.ubuntu.com / 3582-2
Third Party Advisory
usn.ubuntu.com / 3594-1
Third Party Advisory
usn.ubuntu.com / 3597-1
Third Party Advisory
usn.ubuntu.com / 3597-2
Third Party Advisory
usn.ubuntu.com / 3620-2
Third Party Advisory
usn.ubuntu.com / 3690-1
Third Party Advisory
usn.ubuntu.com / 3777-3
Third Party Advisory
usn.ubuntu.com / usn/usn-3516-1
Third Party Advisory
debian.org / security/2018/dsa-4120
Third Party Advisory
debian.org / security/2018/dsa-4187
Third Party Advisory
debian.org / security/2018/dsa-4188
Third Party Advisory
debian.org / security/2018/dsa-4213
Third Party Advisory
exploit-db.com / exploits/43427
ExploitThird Party AdvisoryVDB Entry
kb.cert.org / vuls/id/180049
Third Party AdvisoryUS Government Resource
mitel.com / en-ca/support/security-advisories/mitel-product-security-advisory-18-0001
Third Party Advisory
oracle.com / technetwork/security-advisory/cpujul2019-5072835.html
Third Party Advisory
suse.com / c/suse-addresses-meltdown-spectre-vulnerabilities
Third Party Advisory
synology.com / support/security/Synology_SA_18_01
Third Party Advisory
vmware.com / security/advisories/VMSA-2018-0007.html
Third Party Advisory
vmware.com / us/security/advisories/VMSA-2018-0002.html
Third Party Advisory
vmware.com / us/security/advisories/VMSA-2018-0004.html
Third Party Advisory
arubanetworks.com / assets/alert/ARUBA-PSA-2018-001.txt
Third Party Advisory
arubanetworks.com / assets/alert/ARUBA-PSA-2019-003.txt
Third Party Advisory
kb.cert.org / vuls/id/584653
Third Party AdvisoryUS Government Resource
oracle.com / technetwork/security-advisory/cpujan2018-3236628.html
Third Party Advisory
oracle.com / technetwork/security-advisory/cpujul2018-4258247.html
Third Party Advisory
oracle.com / technetwork/security-advisory/cpuoct2018-4428296.html
Third Party Advisory
securityfocus.com / bid/102376
Third Party AdvisoryVDB Entry
securitytracker.com / id/1040071
Third Party AdvisoryVDB Entry
xenbits.xen.org / xsa/advisory-254.html
Third Party Advisory