Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CVE-2018-12127

CVE information

Published

4 years ago

Last Modified

4 months ago

CVSSv2.0 Severity

Medium

CVSSv3.1 Severity

Medium

Impact Analysis

Description

Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf.

CVSSv2.0 Score

Severity
Medium
Base Score
4.7/10
Exploit Score
3.4/10
Access Vector
Local
Access Complexity
Medium
Authentication Required
None
Impact Score
6.9/10
Confidentiality Impact
Complete
Availability Impact
None
Integrity Impact
None

CVSSv3.1 Score

Severity
Medium
Base Score
5.6/10
Exploit Score
1.1/10
Access Vector
Local
Access Complexity
High
Privileges Required
Low
Impact Score
4/10
Confidentiality Impact
High
Availability Impact
None
Integrity Impact
None
Scope
Changed
User Interaction
None

Products Affected

CPE Affected Vulnerable Excluding Edit
cpe:2.3:o:intel:microarchitectural_load_port_data_sampling_f
  Yes
-
cpe:2.3:h:intel:microarchitectural_load_port_data_sampling:-
  No
-

References