60
CVE-2022-23960
—CVSS 3.1
5.6 medium
EPSS
<1%p41
Published
()
Modified
Description
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
- Vendors
- xenarmdebian
- Products
- xen, cortex-r7 firmware, cortex-r8 firmware, cortex-a57 firmware, cortex-a65 firmware, cortex-a65ae firmware, cortex-a710 firmware, cortex-a72 firmware, cortex-a73 firmware, cortex-a75 firmware, cortex-a76 firmware, cortex-a76ae firmware
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N