CVE-2018-5407

Advisory lineage Upstream: 0 Downstream: 27
Modified
Published: 15 Nov 2018, 21:00
Last modified:05 Aug 2024, 05:33

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
4.7 MEDIUM
v3.1 (nvd)
EPSS Score
0.84% LOW
1% probability +0.20%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

15 Nov 2018, 21:00
Published
Vulnerability first disclosed
05 Aug 2024, 05:33
Last Modified
Vulnerability information updated

Description

Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

CVSS Metrics

  • v3.1MEDIUMScore: 4.7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
  • v2.0LOWScore: 1.9AV:L/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.84% Percentile: 75%

Techniques & Countermeasures

  • CWE-203Observable Discrepancy

    The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • canonicalubuntu_linux

    14.04 | 16.04 | 18.04 | 18.10

  • debiandebian_linux

    8.0 | 9.0

  • nodejsnode.js

    < 6.14.4 | ≥ 8.0.0, < 8.11.4 | ≥ 10.0.0, < 10.9.0

  • UnknownOpenSSL

    ≥ 1.0.2, < 1.0.2q | ≥ 1.1.0, < 1.1.0i

  • oracleapi_gateway

    11.1.2.4.0

  • oracleapplication_server

    0.9.8 | 1.0.0 | 1.0.1

  • oracleenterprise_manager_base_platform

    12.1.0.5.0 | 13.2.0.0.0 | 13.3.0.0.0

  • oracleenterprise_manager_ops_center

    12.3.3

  • oraclemysql_enterprise_backup

    ≤ 3.12.3 | ≥ 3.12.4, ≤ 4.1.2

  • oraclepeoplesoft_enterprise_peopletools

    8.55 | 8.56 | 8.57

  • oracleprimavera_p6_enterprise_project_portfolio_management

    ≥ 17.7, ≤ 17.12 | 8.4 | 15.1 | 15.2 | 16.1 | 16.2 | 18.8

  • oracletuxedo

    12.1.1.0.0

  • oraclevm_virtualbox

    < 6.0.0

  • redhatenterprise_linux_desktop

    7.0

  • redhatenterprise_linux_server

    7.0 | 7.6

  • redhatenterprise_linux_server_aus

    7.6

  • redhatenterprise_linux_server_eus

    7.6

  • redhatenterprise_linux_server_tus

    7.6

  • redhatenterprise_linux_workstation

    7.0

  • tenablenessus

    < 8.1.1

References (28)