Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-28368

Опубликовано: 10 нояб. 2020
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.

A flaw was found in Xen where access to power/energy monitoring interfaces was not properly restricted to privileged software. This flaw allows an unprivileged guest administrator to create covert channels and infer the operations or data used by other contexts within the system, such as AES keys or additional sensitive information. The highest threat from this vulnerability is to confidentiality.

Отчет

This flaw has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in the Extended Life Phase of the support and maintenance life cycle. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Меры по смягчению последствий

There is no known mitigation for this flaw apart from applying the patch.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernel-xenOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-385->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1897145xen: information leak via power sidechannel

EPSS

Процентиль: 21%
0.00067
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
около 5 лет назад

Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.

CVSS3: 4.4
nvd
около 5 лет назад

Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.

CVSS3: 4.4
debian
около 5 лет назад

Xen through 4.14.x allows guest OS administrators to obtain sensitive ...

suse-cvrf
около 5 лет назад

Security update for xen

suse-cvrf
около 5 лет назад

Security update for xen

EPSS

Процентиль: 21%
0.00067
Низкий

5.6 Medium

CVSS3