CVE-2017-5753, known as "Spectre," is a critical side-channel vulnerability affecting microprocessors from various vendors, including Intel and ARM, that utilize speculative execution and branch prediction. An attacker with local user access can exploit this flaw to disclose sensitive information. With a CVSS score of 5.6 (MEDIUM) and a FAUCET Risk Score of 99/100, its high confidentiality impact is due to the complex nature of the attack, requiring specific conditions to succeed. While not listed on the CISA KEV catalog, public exploit code (EDB-43427) exists, and it has garnered significant community discussion and media coverage, indicating widespread awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
c2308CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2308:*:*:*:*:*:*:* | ||
c2316CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2316:*:*:*:*:*:*:* | ||
c2338CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2338:*:*:*:*:*:*:* | ||
c2350CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2350:*:*:*:*:*:*:* | ||
c2358CPE matchmatch criteria | cpe:2.3:h:intel:atom_c:c2358:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Processor Vulnerabilities (Spectre and Meltdown)
Apr 19, 2018hw: cpu: speculative execution bounds-check bypass
Jan 3, 2018Spectre and Meltdown CPU Vulnerabilities Affecting Underlying Operating Systems
Spectre and Meltdown CPU Vulnerabilities