Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-20583

Опубликовано: 01 авг. 2023
Источник: redhat
CVSS3: 2.8

Описание

A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information.

A power side-channel vulnerability was found in AMD processors. This issue may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time, resulting in a sensitive information leak.

Меры по смягчению последствий

Please contact HW vendor for more update on this CVE

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2228322kernel: AMD-SB-7006: potential power side-channel vulnerability in AMD processor

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 4.7
nvd
больше 2 лет назад

A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information.

CVSS3: 4.7
github
больше 2 лет назад

A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information.

CVSS3: 4.7
fstec
больше 2 лет назад

Уязвимость микропрограммного обеспечения процессоров AMD, связанная с раскрытием информации через несоответствие, позволяющая нарушителю получить доступ к конфиденциальной информации

2.8 Low

CVSS3