CVE-2022-48251

EUVD-2022-50960
The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not directly caused by or related to the Arm architecture."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Affected Products (NVD)
VendorProductVersion
armcortex-a53_firmware
-
armcortex-a55_firmware
-
armcortex-a57_firmware
-
armcortex-a72_firmware
-
armcortex-a73_firmware
-
armcortex-a75_firmware
-
armcortex-a76_firmware
-
armcortex-a76ae_firmware
-
armcortex-a77_firmware
-
armcortex-a78_firmware
-
𝑥
= Vulnerable software versions