Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hg2f-7x6w-x2hx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.

Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.

EPSS

Процентиль: 21%
0.00067
Низкий

Дефекты

CWE-203
CWE-862

Связанные уязвимости

CVSS3: 4.4
ubuntu
около 5 лет назад

Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.

CVSS3: 5.6
redhat
около 5 лет назад

Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.

CVSS3: 4.4
nvd
около 5 лет назад

Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.

CVSS3: 4.4
debian
около 5 лет назад

Xen through 4.14.x allows guest OS administrators to obtain sensitive ...

suse-cvrf
около 5 лет назад

Security update for xen

EPSS

Процентиль: 21%
0.00067
Низкий

Дефекты

CWE-203
CWE-862