CVE-2022-23960

Advisory lineage Upstream: 0 Downstream: 14
Modified
Published: 12 Mar 2022, 23:57
Last modified:03 Aug 2024, 03:59

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.6 MEDIUM
v3.1 (nvd)
EPSS Score
0.23% LOW
0% probability +0.05%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Mar 2022, 23:57
Published
Vulnerability first disclosed
03 Aug 2024, 03:59
Last Modified
Vulnerability information updated

Description

Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.

CVSS Metrics

  • v3.1MEDIUMScore: 5.6CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  • v2.0LOWScore: 1.9AV:L/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.23% Percentile: 46%

Affected Systems

  • armcortex-a57_firmware

    na

  • armcortex-a65_firmware

    na

  • armcortex-a65ae_firmware

    na

  • armcortex-a710_firmware

    na

  • armcortex-a72_firmware

    na

  • armcortex-a73_firmware

    na

  • armcortex-a75_firmware

    na

  • armcortex-a76_firmware

    na

  • armcortex-a76ae_firmware

    na

  • armcortex-a77_firmware

    na

  • armcortex-a78_firmware

    na

  • armcortex-a78ae_firmware

    na

  • armcortex-r7_firmware

    na

  • armcortex-r8_firmware

    na

  • armcortex-x1_firmware

    na

  • armcortex-x2_firmware

    na

  • armneoverse_n1_firmware

    na

  • armneoverse_n2_firmware

    na

  • armneoverse-e1_firmware

    na

  • armneoverse-v1_firmware

    na

  • debiandebian_linux

    9.0 | 10.0

  • xenxen

    na

References (5)