7.5

CVE-2025-63094

Exploit
XiangShan Nanhu V2 and XiangShan Kunmighu V3 were discovered to use speculative execution and indirect branch prediction, allowing attackers to access sensitive information via side-channel analysis of the data cache.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xiangshan ≫ Xiangshan Version 2.0
Xiangshan ≫ Xiangshan Version 3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.44
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-203 Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

https://github.com/necst/aca25-xiangshan-spectre/blob/main/README.md
Third Party Advisory
Exploit
https://github.com/necst/aca25-xiangshan-spectre
Third Party Advisory
Exploit