← back
CVE-2017-5753mediumobserved exploitationCWE-203

CVE-2017-5753

85Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 5.6epss 94%
from disclosure to weapon0 days
Published on NVDJan 4
1st PoCJan 3
VulnCheck+3169d
exploitation probability
94%top 1% of all CVEs
observed exploitation
yesVulnCheck
16 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
44 products (894 components)
Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Server EUS (v. 7.3) · Red Hat Enterprise Linux Server (v. 6) · Red Hat Enterprise Linux Server EUS (v. 6.7) · Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) · and others 39
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.