CVE-2018-12130

Advisory lineage Upstream: 0 Downstream: 124
Modified
Published: 30 May 2019, 15:40
Last modified:29 May 2026, 20:08

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
5.9 MEDIUM
v3.1 (nvd)
EPSS Score
0.48% LOW
0% probability +0.06%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 May 2019, 15:40
Published
Vulnerability first disclosed
29 May 2026, 20:08
Last Modified
Vulnerability information updated

Description

Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
  • v3.0MEDIUMScore: 5.6CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  • v2.0MEDIUMScore: 4.7AV:L/AC:M/Au:N/C:C/I:N/A:N

EPSS Trends

Current EPSS score: 0.48% Percentile: 65%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • fedoraprojectfedora

    29

  • intel corporationcentral processing units (cpus)

    A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

  • intelmicroarchitectural_fill_buffer_data_sampling_firmware

    na

References (25)