CVE-2024-2193 is a Speculative Race Condition (SRC) vulnerability affecting modern CPU architectures that support speculative execution, similar to Spectre V1. This flaw allows an unauthenticated attacker to disclose arbitrary data from the CPU by exploiting race conditions within speculative code paths. Rated as Medium severity with a CVSS score of 5.7, the vulnerability requires high privileges (PR:H) and high attack complexity (AC:H) but can lead to high confidentiality (C:H) and integrity (I:H) impacts. While there is no known active exploitation, exploit code, or KEV listing, the vulnerability has garnered significant community attention with two media articles and two community discussions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AMD | CPU | See advisory AMD-SB-7016CNA affected | |
| Xen | Xen | consult Xen advisory XSA-453CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.