CVE-2018-3640, also known as Rogue System Register Read (RSRE) or Variant 3a, is a speculative execution side-channel vulnerability affecting microprocessors from Intel and ARM. It allows a local attacker to potentially disclose sensitive system parameters. The vulnerability has a CVSS score of 5.6 (MEDIUM), indicating a low-privileged local attacker with high attack complexity could achieve high confidentiality impact. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion and media coverage, suggesting considerable interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
c2308CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2308:*:*:*:*:*:*:* | ||
c3308CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c3308:*:*:*:*:*:*:* | ||
c3338CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c3338:*:*:*:*:*:*:* | ||
c3508CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c3508:*:*:*:*:*:*:* | ||
c3538CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c3538:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.