5.5

CVE-2022-21127

Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xen ≫ Xen HwPlatform x86
Intel ≫ Sgx Dcap SwPlatform linux Version < 1.14.100.3
Intel ≫ Sgx Dcap SwPlatform windows Version < 1.14.100.3
Intel ≫ Sgx Psw SwPlatform windows Version < 2.16.100.3
Intel ≫ Sgx Psw SwPlatform linux Version < 2.17.100.3
Intel ≫ Sgx Sdk SwPlatform windows Version < 2.16.100.3
Intel ≫ Sgx Sdk SwPlatform linux Version < 2.17.100.3
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.47% 0.917
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-459 Incomplete Cleanup

The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

http://www.openwall.com/lists/oss-security/2022/06/16/1
Patch
Third Party Advisory
Mailing List
https://www.debian.org/security/2022/dsa-5178
Third Party Advisory
https://security.netapp.com/advisory/ntap-20220624-0008/
Third Party Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00615.html
Patch
Vendor Advisory