Core M3
Vendor:
First CVE: Jan 4, 2018 · Active for 8 years
10
Total CVEs
More Total CVEs than 88% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Core M3 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 4, 2018
8 years ago
Most Recent CVE
Mar 12, 2020
2,325 days ago
CVE Severity & Scoring
Core M310 CVEs
90%
10%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local9 (90.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical1 (10.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (20.0%)
High8 (80.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low9 (90.0%)
High0 (0.0%)
None1 (10.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5753MEDIUM Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side | Jan 4, 2018 | 5.6 | 83 | NO | YES |
CVE-2017-5715MEDIUM Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access v | Jan 4, 2018 | 5.6 | 74 | NO | YES |
CVE-2017-5754MEDIUM Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access v | Jan 4, 2018 | 5.6 | 71 | NO | NO |
CVE-2018-3646MEDIUM Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker | Aug 14, 2018 | 5.6 | 25 | NO | NO |
CVE-2018-3693MEDIUM Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a spec | Jul 10, 2018 | 5.6 | 24 | NO | NO |
CVE-2018-3620MEDIUM Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker | Aug 14, 2018 | 5.6 | 23 | NO | NO |
CVE-2020-0583HIGH Improper access control in the subsystem for Intel(R) Smart Sound Technology may allow an authenticated user to potentially enable escalation of privilege via local access. This af | Mar 12, 2020 | 8.8 | 21 | NO | NO |
CVE-2018-3665MEDIUM System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process | Jun 21, 2018 | 5.6 | 20 | NO | NO |
CVE-2018-9056MEDIUM Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the | Mar 27, 2018 | 5.6 | 20 | NO | NO |
CVE-2018-3619MEDIUM Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encryption may allow an attacker to recover data via physical acces | Jul 10, 2018 | 4.6 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
20.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Core M3
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8100y | 1 | 4.6 | 0.2% | 0 | 0 |
| 7y32 | 8 | 5.6 | 34.4% | 0 | 2 |
| 7y30 | 8 | 5.6 | 34.4% | 0 | 2 |
| 6y30 | 8 | 5.6 | 34.4% | 0 | 2 |