Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-5754

71
FAUCET Score

CVE-2017-5754 affects Intel and Arm microprocessors utilizing speculative execution and indirect branch prediction, allowing local attackers to bypass memory isolation and access sensitive data via side-channel analysis. While the vulnerability carries a Medium CVSS score of 5.6 due to high attack complexity and local access requirements, it presents a critical risk to confidentiality with a FAUCET risk score of 99/100. There is currently no evidence of active exploitation in the CISA KEV or public exploit databases, yet the issue generates exceptional community discussion and media coverage due to its fundamental impact on hardware security.

Impacted Technologies

VendorProductVersion(s)CPE
c2308CPE matchmatch criteria
cpe:2.3:h:intel:atom_c:c2308:*:*:*:*:*:*:*
c2316CPE matchmatch criteria
cpe:2.3:h:intel:atom_c:c2316:*:*:*:*:*:*:*
c2338CPE matchmatch criteria
cpe:2.3:h:intel:atom_c:c2338:*:*:*:*:*:*:*
c2350CPE matchmatch criteria
cpe:2.3:h:intel:atom_c:c2350:*:*:*:*:*:*:*
c2358CPE matchmatch criteria
cpe:2.3:h:intel:atom_c:c2358:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.6MEDIUM

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.1
Impact Score
4.0
CvssVersion
3.0

Exploit Intelligence

EPSS Score
84.17%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.8417 is in the 100th percentile among its peer group of 1,295 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (23)

3cxpatch availablevia llm_extracted
View patch
coollabspatch availablevia llm_extracted
libreofficepatch availablevia llm_extracted
Fixed in: OpenVPN Access Server bundled Clients Package v14
View patch
microsoftpatch availablevia nvd_reference
View patch
openvpnpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.5 Advanced Update SupportFixed in: kernel-0:2.6.32-431.85.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.6 Advanced Update SupportFixed in: kernel-0:2.6.32-504.64.4.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.6 Telco Extended Update SupportFixed in: kernel-0:2.6.32-504.64.4.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.7 Extended Update SupportFixed in: kernel-0:2.6.32-573.55.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-693.11.1.rt56.639.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-862.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.9 Long LifeFixed in: kernel-0:2.6.18-348.35.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Advanced Update SupportFixed in: kernel-0:3.10.0-327.62.4.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Telco Extended Update SupportFixed in: kernel-0:3.10.0-327.62.4.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-327.62.4.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Extended Update SupportFixed in: kernel-0:3.10.0-514.48.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-693.11.1.rt56.606.el6rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt-0:4.14.0-49.2.2.el7a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5 Extended Lifecycle SupportFixed in: kernel-0:2.6.18-426.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-696.28.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.2 Advanced Update SupportFixed in: kernel-0:2.6.32-220.76.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.4 Advanced Update SupportFixed in: kernel-0:2.6.32-358.84.2.el6
View patch
samrocketmanpatch availablevia llm_extracted
View patch

Vendor Advisories (6)

coollabsllm-coollabs-861bcc8082959b4eCRITICAL

Processor Vulnerabilities (Spectre and Meltdown)

Apr 19, 2018
samrocketmanllm-samrocketman-edf8c2b7c0a17cd6HIGH

NR18-03

Jan 12, 2018
3cxllm-3cx-73c744a2212e3100HIGH

NR18-03

Jan 12, 2018
redhatCVE-2017-5754Important

hw: cpu: speculative execution permission faults handling

Jan 3, 2018
openvpnllm-openvpn-1db827e286909e83

Spectre and Meltdown CPU Vulnerabilities Affecting Underlying Operating Systems

libreofficellm-libreoffice-ff72b84b661c0888

Spectre and Meltdown CPU Vulnerabilities

References

lists.opensuse.org / opensuse-security-announce/2018-01/msg00006.html
lists.opensuse.org / opensuse-security-announce/2018-01/msg00007.html
lists.opensuse.org / opensuse-security-announce/2018-01/msg00008.html
lists.opensuse.org / opensuse-security-announce/2018-01/msg00014.html
lists.opensuse.org / opensuse-security-announce/2018-01/msg00016.html
nvidia.custhelp.com / app/answers/detail/a_id/4609
Third Party Advisory
nvidia.custhelp.com / app/answers/detail/a_id/4611
nvidia.custhelp.com / app/answers/detail/a_id/4613
nvidia.custhelp.com / app/answers/detail/a_id/4614
access.redhat.com / errata/RHSA-2018:0292
access.redhat.com / security/vulnerabilities/speculativeexecution
Third Party Advisory
aws.amazon.com / de/security/security-bulletins/AWS-2018-013
Third Party Advisory
blog.mozilla.org / security/2018/01/03/mitigations-landing-new-class-timing-attack
Third Party Advisory
cdrdv2.intel.com / v1/dl/getContent/685358
cert-portal.siemens.com / productcert/pdf/ssa-608355.pdf
cert.vde.com / en-us/advisories/vde-2018-002
cert.vde.com / en-us/advisories/vde-2018-003
developer.arm.com / support/arm-security-updates/speculative-processor-vulnerability
googleprojectzero.blogspot.com / 2018/01/reading-privileged-memory-with-side.html
Third Party Advisory
help.ecostruxureit.com / display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
help.ecostruxureit.com / display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes
lists.debian.org / debian-lts-announce/2018/01/msg00004.html
meltdownattack.com
Technical DescriptionThird Party Advisory
portal.msrc.microsoft.com / en-US/security-guidance/advisory/ADV180002
PatchThird Party AdvisoryVendor Advisory
security.freebsd.org / advisories/FreeBSD-SA-18:03.speculative_execution.asc
security.gentoo.org / glsa/201810-06
security.googleblog.com / 2018/01/todays-cpu-vulnerability-what-you-need.html
Third Party Advisory
security.netapp.com / advisory/ntap-20180104-0001
source.android.com / security/bulletin/2018-04-01
support.citrix.com / article/CTX231399
support.citrix.com / article/CTX234679
support.f5.com / csp/article/K91229003
Third Party Advisory
support.hpe.com / hpsc/doc/public/display
support.hpe.com / hpsc/doc/public/display
support.lenovo.com / us/en/solutions/LEN-18282
Third Party Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannel
usn.ubuntu.com / 3522-3
usn.ubuntu.com / 3522-4
usn.ubuntu.com / 3523-1
usn.ubuntu.com / 3540-2
usn.ubuntu.com / 3541-2
usn.ubuntu.com / 3583-1
usn.ubuntu.com / 3597-1
usn.ubuntu.com / 3597-2
usn.ubuntu.com / usn/usn-3516-1
usn.ubuntu.com / usn/usn-3522-2
usn.ubuntu.com / usn/usn-3523-2
usn.ubuntu.com / usn/usn-3524-2
usn.ubuntu.com / usn/usn-3525-1
codeaurora.org / security-bulletin/2018/07/02/july-2018-code-aurora-security-bulletin
debian.org / security/2018/dsa-4078
debian.org / security/2018/dsa-4082
debian.org / security/2018/dsa-4120
kb.cert.org / vuls/id/180049
mitel.com / en-ca/support/security-advisories/mitel-product-security-advisory-18-0001
oracle.com / security-alerts/cpuapr2020.html
oracle.com / technetwork/security-advisory/cpuapr2019-5072813.html
suse.com / c/suse-addresses-meltdown-spectre-vulnerabilities
Third Party Advisory
synology.com / support/security/Synology_SA_18_01
Third Party Advisory
arubanetworks.com / assets/alert/ARUBA-PSA-2018-001.txt
arubanetworks.com / assets/alert/ARUBA-PSA-2019-003.txt
kb.cert.org / vuls/id/584653
Third Party AdvisoryUS Government Resource
securityfocus.com / bid/102378
securityfocus.com / bid/106128
securitytracker.com / id/1040071
Third Party AdvisoryVDB Entry
xenbits.xen.org / xsa/advisory-254.html
Third Party Advisory