CVE-2018-3615
6.4
MEDIUM
CVSS 3.1
EPSS 1.7%
Description
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.
How to fix CVE-2018-3615
To remediate CVE-2018-3615, upgrade the affected package to a fixed version below.
- Debian/intel-microcode—upgrade to 3.20180703.1 or later
Is CVE-2018-3615 being exploited?
Low — EPSS is 1.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.20180703.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.4 | CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N |