Information Exposure Through Microarchitectural State
CVE-2023-28746

6.5MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 March 2024

Badges

📰 News Worthy

Summary

The vulnerability arises due to information exposure through microarchitectural state after transient execution from specific register files on certain Intel Atom processors. This flaw permits an authenticated user to potentially enable unauthorized disclosure of sensitive information through local access. Affected users who can execute code on the system might exploit this condition to gain access to confidential data, emphasizing the need for vigilance and security measures in deploying these processors.

Affected Version(s)

Intel(R) Atom(R) Processors See references

News Articles

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 📰

    First article discovered by XCP-ng

  • Vulnerability published

  • Vulnerability Reserved

.