5.6

CVE-2022-23960

Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
XenXen Version-
   ArmCortex-a57 Version-
   ArmCortex-a65 Version-
   ArmCortex-a65ae Version-
   ArmCortex-a710 Version-
   ArmCortex-a72 Version-
   ArmCortex-a73 Version-
   ArmCortex-a75 Version-
   ArmCortex-a76 Version-
   ArmCortex-a76ae Version-
   ArmCortex-a77 Version-
   ArmCortex-a78 Version-
   ArmCortex-a78ae Version-
   ArmCortex-r7 Version-
   ArmCortex-r8 Version-
   ArmCortex-x1 Version-
   ArmCortex-x2 Version-
   ArmNeoverse-e1 Version-
   ArmNeoverse-v1 Version-
   ArmNeoverse N1 Version-
   ArmNeoverse N2 Version-
ArmCortex-r7 Firmware Version-
   ArmCortex-r7 Version-
ArmCortex-r8 Firmware Version-
   ArmCortex-r8 Version-
ArmCortex-a57 Firmware Version-
   ArmCortex-a57 Version-
ArmCortex-a65 Firmware Version-
   ArmCortex-a65 Version-
ArmCortex-a65ae Firmware Version-
   ArmCortex-a65ae Version-
ArmCortex-a710 Firmware Version-
   ArmCortex-a710 Version-
ArmCortex-a72 Firmware Version-
   ArmCortex-a72 Version-
ArmCortex-a73 Firmware Version-
   ArmCortex-a73 Version-
ArmCortex-a75 Firmware Version-
   ArmCortex-a75 Version-
ArmCortex-a76 Firmware Version-
   ArmCortex-a76 Version-
ArmCortex-a76ae Firmware Version-
   ArmCortex-a76ae Version-
ArmCortex-a77 Firmware Version-
   ArmCortex-a77 Version-
ArmCortex-a78 Firmware Version-
   ArmCortex-a78 Version-
ArmCortex-a78ae Firmware Version-
   ArmCortex-a78ae Version-
ArmCortex-x1 Firmware Version-
   ArmCortex-x1 Version-
ArmCortex-x2 Firmware Version-
   ArmCortex-x2 Version-
ArmNeoverse-e1 Firmware Version-
   ArmNeoverse-e1 Version-
ArmNeoverse-v1 Firmware Version-
   ArmNeoverse-v1 Version-
ArmNeoverse N1 Firmware Version-
   ArmNeoverse N1 Version-
ArmNeoverse N2 Firmware Version-
   ArmNeoverse N2 Version-
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.352
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.6 1.1 4
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvd@nist.gov 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:P/I:N/A:N