CVE-2018-3693 is a speculative execution side-channel vulnerability affecting microprocessors from vendors like ARM, Intel, and Fujitsu, allowing local attackers to disclose sensitive information. With a CVSS score of 5.6 (Medium), it requires local user access and high attack complexity, but can lead to high confidentiality impact. While not listed in CISA KEV and lacking public exploit code in Metasploit or ExploitDB, it has garnered significant community discussion and media coverage, indicating notable awareness despite its inactive Hot List status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
c2308CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2308:*:*:*:*:*:*:* | ||
c2316CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2316:*:*:*:*:*:*:* | ||
c2338CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2338:*:*:*:*:*:*:* | ||
c2350CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2350:*:*:*:*:*:*:* | ||
c2358CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2358:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.