CVE-2018-5407
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 3.4%
from disclosure to weapon0 days
Published on NVDNov 15
1st PoCNov 2
exploitation probability
3.4%top 12% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
Affected products
N/A · Processors supporting Simultaneous Multi-Threadingpublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/45785unverifiedcve_referencewww.exploit-db.com/exploits/45785/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://access.redhat.com/errata/RHSA-2019:0483https://access.redhat.com/errata/RHSA-2019:0651https://access.redhat.com/errata/RHSA-2019:0652https://access.redhat.com/errata/RHSA-2019:2125https://access.redhat.com/errata/RHSA-2019:3929https://access.redhat.com/errata/RHSA-2019:3931https://access.redhat.com/errata/RHSA-2019:3932https://access.redhat.com/errata/RHSA-2019:3933https://access.redhat.com/errata/RHSA-2019:3935https://eprint.iacr.org/2018/1060.pdfhttps://github.com/bbbrumley/portsmashhttps://lists.debian.org/debian-lts-announce/2018/11/msg00024.html