cbcvebase.
CVE-2017-5754
published 2018-01-04

CVE-2017-5754: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker…

PriorityP350medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
84.17%
99.7th percentile
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

Affected

916 ranges· showing 25
VendorProductVersion rangeFixed in
appleios
applemacos_high_sierra_10.13.2_security_update_2017-002_sierra_and_security_update_20
applemacos_high_sierra_10.13.3_security_update_2018-001_sierra_and_security_update_20
appletvos
applewatchos
armcortex-a
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
debiandebian_linux
debianlinux< linux 4.14.12-1 (bookworm)linux 4.14.12-1 (bookworm)
debiannvidia-graphics-drivers< linux 4.14.12-1 (bookworm)linux 4.14.12-1 (bookworm)
debiannvidia-graphics-drivers-legacy-340xx< linux 4.14.12-1 (bookworm)linux 4.14.12-1 (bookworm)
debianxen< xen 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 (bookworm)xen 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 (bookworm)
debianxen< xen 4.11.1-1 (bookworm)xen 4.11.1-1 (bookworm)
debianxen< linux 4.14.12-1 (bookworm)linux 4.14.12-1 (bookworm)
googleandroid
intelatom_c
intelatom_c
intelatom_c
intelatom_c
intelatom_c
intelatom_c
intelatom_c

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2017-5754 exploits speculative execution at the hardware level, not a software flaw — detection should focus on microarchitectural side-channel behaviour rather than software artifacts
  • Use authenticated vulnerability scans or endpoint agents to identify systems missing Meltdown/Spectre patches; over 75 QIDs exist to determine patch state
  • ·Intel firmware updates for Broadwell and Haswell CPUs were pulled due to causing unexpected reboots and potential data loss/corruption — deploying those microcode versions may destabilise systems
  • ·Virtual scanner appliances can still be indirectly affected by CVE-2017-5754 if the vulnerability is exploitable at the hypervisor level; the underlying hypervisor must be patched separately

CVSS provenance

nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv3.05.6MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_cisco5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.