Transient Execution Vulnerability in AMD Processors
CVE-2024-36350

5.6MEDIUM

What is CVE-2024-36350?

A transient execution vulnerability found in various AMD processors could enable an attacker to deduce sensitive data from prior memory operations. This could lead to the unintended exposure of confidential information, making it crucial for users and organizations to remain vigilant and apply necessary security measures.

Affected Version(s)

AMD EPYC™ 7003 Series Processors MilanPI 1.0.0.G + OS Updates

AMD EPYC™ 8004 Series Processors GenoaPI 1.0.0.E + OS Updates

AMD EPYC™ 9004 Series Processors GenoaPI 1.0.0.E + OS Updates

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.