5.5
CVE-2023-5370
- EPSS 0.14%
- Veröffentlicht 04.10.2023 04:15:15
- Zuletzt bearbeitet 21.11.2024 08:41:37
- Quelle secteam@freebsd.org
- CVE-Watchlists
- Unerledigt
arm64 boot CPUs may lack speculative execution protections
On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no speculative execution workarounds being installed on CPU 0.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.343 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-665 Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.