CVE-2018-9056 is a medium-severity side-channel vulnerability affecting microprocessors from ARM and Intel that utilize speculative execution. An attacker with local user access can exploit this flaw to potentially disclose sensitive information through a directional branch predictor side-channel attack, known as BranchScope. While the CVSS score is 5.6 (Medium) due to high confidentiality impact and high attack complexity, there is no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion beyond a single media article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
c2308CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2308:*:*:*:*:*:*:* | ||
c2316CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2316:*:*:*:*:*:*:* | ||
c2338CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2338:*:*:*:*:*:*:* | ||
c2350CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2350:*:*:*:*:*:*:* | ||
c2358CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2358:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.