CVE-2018-3615
published 2018-08-14CVE-2018-3615: Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information…
PriorityP341high7.3CVSS 3.1
AVLACLPRLUINSCCHILAN
EPSS
6.30%
92.8th percentile
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.
Affected
107 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20180703.1 (bookworm) | intel-microcode 3.20180703.1 (bookworm) |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i3 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
| intel | core_i5 | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
nvdv3.06.4MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
nvdv2.05.4MEDIUMAV:L/AC:M/Au:N/C:C/I:P/A:N
osv6.4MEDIUM
vendor_cisco6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2018-0011 Information about L1 Terminal Fault findings
vendor_paloalto·2018-08-17·CVSS 6.4
CVE-2018-3615 [MEDIUM] CWE-200 PAN-SA-2018-0011 Information about L1 Terminal Fault findings
PAN-SA-2018-0011 Information about L1 Terminal Fault findings
Palo Alto Networks is aware of recent vulnerability disclosures, known as L1 Terminal Fault, that affect modern CPU architectures. At this time, our findings show that these vulnerabilities pose no increased risk to Palo Alto Networks PAN-OS devices. (CVE-2018-3615, CVE-2018-3620, and CVE-2018-3646). This security advisory will be updated as more information becomes available or if there are changes in the impact of these vulnerabilities. PAN-OS/Panorama platforms are not directly impacted by these vulnerabilities, as successful
CVEs: CVE-2018-3615, CVE-2018-3620, CVE-2018-3646
Affected products: PAN-OS, Panorama
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
vendor_cisco·2018-08-14·CVSS 6.4
CVE-2018-3615 [MEDIUM] CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
5On August 14th, 2018, three vulnerabilities were disclosed by Intel and security researchers that leverage a speculative execution side-channel method referred to as L1 Terminal Fault (L1TF) that affects modern Intel microprocessors. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes.
The first vulnerability, CVE-2018-3615, affects Intel SGX technology and is referred to by the researchers who discovered it as foreshadow. This vulnerability is not known to affect any Cisco devices as the Cisco devices do not utilize Intel SGX technology.
The second vulnerability, CVE-2018-3620, and the third vulnerability, CVE-2018-3646, ar
Debian
CVE-2018-3615: intel-microcode - Systems with microprocessors utilizing speculative execution and Intel software ...
vendor_debian·2018·CVSS 6.4
CVE-2018-3615 [MEDIUM] CVE-2018-3615: intel-microcode - Systems with microprocessors utilizing speculative execution and Intel software ...
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.
Scope: local
bookworm: resolved (fixed in 3.20180703.1)
bullseye: resolved (fixed in 3.20180703.1)
forky: resolved (fixed in 3.20180703.1)
sid: resolved (fixed in 3.20180703.1)
trixie: resolved (fixed in 3.20180703.1)
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
vendor_cisco
CVE-2018-3646 CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
CVE-2018-3646: CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
5On August 14th, 2018, three vulnerabilities were disclosed by Intel and security researchers that leverage a speculative execution side-channel method referred to as L1 Terminal Fault (L1TF) that affects modern Intel microprocessors. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes. The first vulnerability, CVE-2018-3615, affects Intel SGX technology and is referred to by the researchers who discovered it as foreshadow. This vulnerability is not known to affect any Cisco devices as the Cisco devices do not utilize Intel SGX technology. The second vulnerability, CVE-2018-3620, and the third vulnerability, CVE
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
vendor_cisco
CVE-2018-3620 CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
CVE-2018-3620: CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
5On August 14th, 2018, three vulnerabilities were disclosed by Intel and security researchers that leverage a speculative execution side-channel method referred to as L1 Terminal Fault (L1TF) that affects modern Intel microprocessors. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes. The first vulnerability, CVE-2018-3615, affects Intel SGX technology and is referred to by the researchers who discovered it as foreshadow. This vulnerability is not known to affect any Cisco devices as the Cisco devices do not utilize Intel SGX technology. The second vulnerability, CVE-2018-3620, and the third vulnerability, CVE
Red Hat
CVE-2018-3615: Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of info
vendor_redhat·CVSS 6.4
CVE-2018-3615 [MEDIUM] CVE-2018-3615: Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of info
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.
Statement: Not vulnerable. This issue did not affect the versions of kernel as shipped with any Red Hat product.
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
vendor_cisco
CVE-2018-3615 CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
CVE-2018-3615: CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
5On August 14th, 2018, three vulnerabilities were disclosed by Intel and security researchers that leverage a speculative execution side-channel method referred to as L1 Terminal Fault (L1TF) that affects modern Intel microprocessors. These vulnerabilities could allow an unprivileged, local attacker, in specific circumstances, to read privileged memory belonging to other processes. The first vulnerability, CVE-2018-3615, affects Intel SGX technology and is referred to by the researchers who discovered it as foreshadow. This vulnerability is not known to affect any Cisco devices as the Cisco devices do not utilize Intel SGX technology. The second vulnerability, CVE-2018-3620, and the third vulnerability, CVE
GHSA
GHSA-9w6j-7396-jgw4: Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of info
ghsa_unreviewed·2022-05-13
CVE-2018-3615 [MEDIUM] CWE-203 GHSA-9w6j-7396-jgw4: Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of info
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.
OSV
CVE-2018-3615: Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of info
osv·2018-08-14·CVSS 6.4
CVE-2018-3615 [MEDIUM] CVE-2018-3615: Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of info
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.
Kernel
Merge branch 'l1tf-final' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
kernel_security·2018-08-14·CVSS 6.4
CVE-2018-3615 [MEDIUM] Merge branch 'l1tf-final' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Merge branch 'l1tf-final' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Merge L1 Terminal Fault fixes from Thomas Gleixner:
"L1TF, aka L1 Terminal Fault, is yet another speculative hardware
engineering trainwreck. It's a hardware vulnerability which allows
unprivileged speculative access to data which is available in the
Level 1 Data Cache when the page table entry controlling the virtual
address, which is used for the access, has the Present bit cleared or
other reserved bits set.
If an instruction accesses a virtual address for which the relevant
page table entry (PTE) has the Present bit cleared or other reserved
bits set, then speculative execution ignores the invalid PTE and loads
the referenced data if it is present in the Level 1 Data Cache, as if
the page referenced by
No detection rules found.
No public exploits indexed.
Tenable
Foreshadow: Speculative Execution Attack Targets Intel SGX
blogs_tenable·2018-08-14
Foreshadow: Speculative Execution Attack Targets Intel SGX
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Foreshadow: Speculative Execution Attack Targets Intel SGX
blogs_tenable·2018-08-14·CVSS 6.4
[MEDIUM] Foreshadow: Speculative Execution Attack Targets Intel SGX
Blog / Cyber Exposure Alerts
Subscribe
# Foreshadow: Speculative Execution Attack Targets Intel SGX
Ryan Seguin
August 14, 2018
2 Min Read
A flaw in Intel’s Software Guard Extensions implementation allows an attacker to access data stored in memory of other applications running on the same host, without the need for privilege escalation.
## Background
Researchers discovered a flaw in Intel’s Software Guard Extensions (SGX) implementation that opens up a new speculative execution attack called Foreshadow (CVE-2018-3615). In addition, Intel has discovered variants allowing for Foreshadow attacks against microprocessors, system management mode (SMM) code, operating systems and Hypervisor software. These variants have been dubbed Foreshadow-NG (CVE-2018-3620 and CVE-2018-3646).
Collect
http://support.lenovo.com/us/en/solutions/LEN-24163http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180815-01-cpu-enhttp://www.securityfocus.com/bid/105080http://www.securitytracker.com/id/1041451https://cert-portal.siemens.com/productcert/pdf/ssa-254686.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://foreshadowattack.eu/https://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0008https://security.netapp.com/advisory/ntap-20180815-0001/https://software.intel.com/security-software-guidance/software-guidance/l1-terminal-faulthttps://support.f5.com/csp/article/K35558453https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03874en_ushttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180814-cpusidechannelhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.htmlhttps://www.kb.cert.org/vuls/id/982149https://www.synology.com/support/security/Synology_SA_18_45http://support.lenovo.com/us/en/solutions/LEN-24163http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180815-01-cpu-enhttp://www.securityfocus.com/bid/105080http://www.securitytracker.com/id/1041451https://cert-portal.siemens.com/productcert/pdf/ssa-254686.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://foreshadowattack.eu/https://lists.debian.org/debian-lts-announce/2018/09/msg00017.htmlhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0008https://security.netapp.com/advisory/ntap-20180815-0001/https://software.intel.com/security-software-guidance/software-guidance/l1-terminal-faulthttps://support.f5.com/csp/article/K35558453https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03874en_ushttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180814-cpusidechannelhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.htmlhttps://www.kb.cert.org/vuls/id/982149https://www.synology.com/support/security/Synology_SA_18_45
2018-08-14
Published