CVE-2022-0002 describes a non-transparent sharing of the branch predictor in some Intel processors, potentially allowing an authorized local user to disclose information. This vulnerability is rated Medium severity (CVSS 6.5), indicating a local attack vector with low complexity, requiring low privileges, and leading to high confidentiality impact. While there are no known public exploits or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness within the security community. It is not currently listed on CISA's KEV catalog and is inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:intel:atom_c3308:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:intel:atom_c3336:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:intel:atom_c3338:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:intel:atom_c3338r:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:intel:atom_c3436l:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.