CVE-2017-5926

EUVD-2017-15001
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
Affected Products (NVD)
VendorProductVersion
allwinnera64
-
amdathlon_ii_640_x4
-
amde-350
-
amdfx-8120_8-core
-
amdfx-8320_8-core
-
amdfx-8350_8-core
-
amdphenom_9550_4-core
-
intelatom_c2750
-
intelceleron_n2840
-
intelcore_i5_m480
-
intelcore_i7-2620qm
-
intelcore_i7-3632qm
-
intelcore_i7-4500u
-
intelcore_i7-6700k
-
intelcore_i7_920
-
intelxeon_e3-1240_v5
-
intelxeon_e5-2658_v2
-
nvidiategra_k1_cd570m-a1
-
nvidiategra_k1_cd580m-a1
-
samsungexynos_5800
-
𝑥
= Vulnerable software versions