CVE-2020-28368
published 2020-11-10CVE-2020-28368: Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a…
PriorityP419medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.39%
31.9th percentile
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.14.0+80-gd101b417b7-1 (bookworm) | xen 4.14.0+80-gd101b417b7-1 (bookworm) |
| fedoraproject | fedora | — | — |
| xen | xen | <= 4.14.0 | — |
| xen | xen | >= 0 < 4.14.0+80-gd101b417b7-1 | 4.14.0+80-gd101b417b7-1 |
| xen | xen | >= 0 < 4.14.0+80-gd101b417b7-1 | 4.14.0+80-gd101b417b7-1 |
| xen | xen | >= 0 < 4.14.0+80-gd101b417b7-1 | 4.14.0+80-gd101b417b7-1 |
| xen | xen | >= 0 < 4.14.0+80-gd101b417b7-1 | 4.14.0+80-gd101b417b7-1 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hg2f-7x6w-x2hx: Xen through 4
ghsa_unreviewed·2022-05-24
CVE-2020-28368 [MEDIUM] CWE-203 GHSA-hg2f-7x6w-x2hx: Xen through 4
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.
OSV
CVE-2020-28368: Xen through 4
osv·2020-11-10·CVSS 4.4
CVE-2020-28368 [MEDIUM] CVE-2020-28368: Xen through 4
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.
Red Hat
xen: information leak via power sidechannel
vendor_redhat·2020-11-10·CVSS 4.4
CVE-2020-28368 [MEDIUM] CWE-385 xen: information leak via power sidechannel
xen: information leak via power sidechannel
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.
A flaw was found in Xen where access to power/energy monitoring interfaces was not properly restricted to privileged software. This flaw allows an unprivileged guest administrator to create covert channels and infer the operations or data used by other contexts within the system, such as AES keys or additional sensitive information. The highest threat from this vulnerability is to confidentiality.
Statement: This flaw has
Debian
CVE-2020-28368: xen - Xen through 4.14.x allows guest OS administrators to obtain sensitive informatio...
vendor_debian·2020·CVSS 4.4
CVE-2020-28368 [MEDIUM] CVE-2020-28368: xen - Xen through 4.14.x allows guest OS administrators to obtain sensitive informatio...
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.
Scope: local
bookworm: resolved (fixed in 4.14.0+80-gd101b417b7-1)
bullseye: resolved (fixed in 4.14.0+80-gd101b417b7-1)
forky: resolved (fixed in 4.14.0+80-gd101b417b7-1)
sid: resolved (fixed in 4.14.0+80-gd101b417b7-1)
trixie: resolved (fixed in 4.14.0+80-gd101b417b7-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2020/11/26/1http://xenbits.xen.org/xsa/advisory-351.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5J66QUUHXH2RR4CNCKQRGVXVSOUFRPDA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XV23EZIMNLJN4YXRRXLQV2ALW6ZEALXV/https://platypusattack.comhttps://www.debian.org/security/2020/dsa-4804https://www.zdnet.com/article/new-platypus-attack-can-steal-data-from-intel-cpus/https://xenbits.xen.org/xsa/advisory-351.htmlhttp://www.openwall.com/lists/oss-security/2020/11/26/1http://xenbits.xen.org/xsa/advisory-351.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5J66QUUHXH2RR4CNCKQRGVXVSOUFRPDA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XV23EZIMNLJN4YXRRXLQV2ALW6ZEALXV/https://platypusattack.comhttps://www.debian.org/security/2020/dsa-4804https://www.zdnet.com/article/new-platypus-attack-can-steal-data-from-intel-cpus/https://xenbits.xen.org/xsa/advisory-351.html
2020-11-10
Published