Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-20583

Опубликовано: 01 авг. 2023
Источник: redhat
CVSS3: 2.8
EPSS Низкий

Описание

A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information.

A power side-channel vulnerability was found in AMD processors. This issue may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time, resulting in a sensitive information leak.

Меры по смягчению последствий

Please contact HW vendor for more update on this CVE

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2228322kernel: AMD-SB-7006: potential power side-channel vulnerability in AMD processor

EPSS

Процентиль: 15%
0.00237
Низкий

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 4.7
nvd
около 3 лет назад

A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information.

CVSS3: 4.7
github
около 3 лет назад

A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information.

CVSS3: 4.7
fstec
около 3 лет назад

Уязвимость микропрограммного обеспечения процессоров AMD, связанная с раскрытием информации через несоответствие, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 15%
0.00237
Низкий

2.8 Low

CVSS3

Уязвимость CVE-2023-20583