Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
CVSS Details
- CVSS 3.1 Base Score: 5.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Microcode | — | Apply Apple macOS Security Update 2018-002 High Sierra | Oct 31, 2018 | Oct 30, 2018 |
| Cisco Xe | — | Upgrade to the latest version of Cisco IOS XE | Jul 30, 2019 | May 22, 2018 |
| Debian | — | Upgrade intel-microcode | Aug 18, 2018 | May 22, 2018 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 3, 2018 |
| Suse | — | Upgrade ucode-intelUpgrade microcode_ctl | Jul 7, 2018 | May 22, 2018 |
| Ubuntu | — | Upgrade intel-microcode | Sep 11, 2018 | May 22, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub