ZeroHour

CVE-2018-5407

PoC ×2
CVSS 3.1
4.7 medium
EPSS
3%p88
Published
()
Modified
Description

Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

Vendors
canonicaldebiannodejsopenssltenableoracleredhat
Products
ubuntu linux, debian linux, node.js, openssl, nessus, api gateway, application server, enterprise manager base platform, enterprise manager ops center, mysql enterprise backup, peoplesoft enterprise peopletools, primavera p6 enterprise project portfolio management
Weakness
CWE-200, CWE-203
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news