CWE-1421Base

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution

Incomplete in the CWE catalog · 4 CVEs mapped

4
CVEs mapped
5.7
Median CVSS
What it is

A processor event may allow transient operations to access

architecturally restricted data (for example, in another address

space) in a shared microarchitectural structure (for example, a CPU

cache), potentially exposing the data over a covert channel.

Recent examples
5.6cvss
CVE-2024-36357

A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of…

A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.

MEDIUMno explanation yet
0%
epss
5.6cvss
CVE-2024-36350

A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of…

A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.

MEDIUMno explanation yet
0%
epss
5.7cvss
CVE-2024-28956

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated…

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1421
Abstraction
Base
Structure
Simple
Status
Incomplete
References (15)