← Vulnerability feed

Vulnerability record · CVE-2017-5715 · published 4 January 2018

CVE-2017-5715: Intel CPUs speculative execution side-channel information disclosure

Intel · Atom C

CVE-2017-5715 is the Spectre variant 2 flaw in Intel microprocessors that use speculative execution and indirect branch prediction. A local attacker can use side-channel analysis to read data that the processor speculatively accessed, potentially exposing sensitive information from other processes or the kernel. The issue affects a broad range of Intel Atom, Celeron, Pentium, Core, and Xeon products.

5.6 CVSS 3.1 Medium EPSS 74% · top 0.5% CWE-203 · Observable discrepancy
5.6CVSS 3.1 base score, v2 1.9
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
188References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityAlthough the CVSS base score is medium, the flaw affects a very large installed base of Intel processors, has public exploit code, and carries a very high EPSS probability.

What it is

CVE-2017-5715 is the Spectre variant 2 flaw in Intel microprocessors that use speculative execution and indirect branch prediction. A local attacker can use side-channel analysis to read data that the processor speculatively accessed, potentially exposing sensitive information from other processes or the kernel. The issue affects a broad range of Intel Atom, Celeron, Pentium, Core, and Xeon products.

Impact

An attacker with local user access can disclose information from memory that should not be accessible, including secrets belonging to other processes or the operating system. The CVSS vector shows high confidentiality impact with no integrity or availability impact.

Attack surface

The attack is local (AV:L) and requires low privileges (PR:L) with no user interaction (UI:N). It is reached by executing crafted code on the same system and measuring timing or other side-channel effects.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.74041, 99.459th percentile) and a public proof-of-concept is referenced, indicating active interest and available exploit code.

What to do

  • Apply vendor microcode and operating system updates that implement mitigations for Spectre variant 2.
  • Enable available kernel and hypervisor mitigations such as retpoline, IBRS, or IBPB where supported.
  • Limit local interactive access and enforce least privilege to reduce the number of users who can run side-channel code.
  • Consider disabling simultaneous multithreading (SMT) on systems where the risk of cross-thread leakage is unacceptable.
  • Monitor vendor advisories for updated firmware and software fixes for affected Intel processor families.

Detection

  • Monitor for execution of known Spectre proof-of-concept binaries or unusual high-resolution timing code.
  • Audit systems for missing microcode or kernel patches related to CVE-2017-5715.
  • Track local user behavior that repeatedly measures cache or branch timing, which may indicate side-channel probing.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00002.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00003.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00004.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00005.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00009.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00012.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00013.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html Broken Link
http://nvidia.custhelp.com/app/answers/detail/a_id/4609 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4611 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4613 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4614 Third Party Advisory
http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.html Third Party AdvisoryVDB Entry
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt Third Party Advisory
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt Third Party Advisory
http://www.kb.cert.org/vuls/id/584653 Third Party AdvisoryUS Government Resource
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html Third Party Advisory
http://www.securityfocus.com/bid/102376 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040071 Third Party AdvisoryVDB Entry
http://xenbits.xen.org/xsa/advisory-254.html Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0292 Third Party Advisory
https://access.redhat.com/security/vulnerabilities/speculativeexecution Third Party Advisory
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ Third Party Advisory
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf Third Party Advisory
https://cert.vde.com/en-us/advisories/vde-2018-002 Third Party Advisory
https://cert.vde.com/en-us/advisories/vde-2018-003 Third Party Advisory
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability Third Party Advisory
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html Third Party Advisory
https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00015.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00016.html Mailing ListThird Party Advisory

Track CVE-2017-5715 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-24489Intel atom x5-e3930 vulnerabilityIncomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.EPSS 0.35%7.8CVE-2020-0559Intel ac 3165 firmware incorrect permission assignment vulnerabilityInsecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticat…EPSS 0.29%7.6CVE-2018-3652Intel xeon e3 information exposure vulnerabilityExisting UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable p…EPSS 0.37%6.8CVE-2021-33150Intel atom c2308 vulnerabilityHardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an unauthenticated user to potenti…EPSS 0.35%6.5CVE-2022-0002Intel atom c3308 vulnerabilityNon-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable informati…EPSS 0.45%6.0CVE-2017-5703Intel core i7-8550u improper privilege management vulnerabilityConfiguration of SPI Flash in platforms based on multiple Intel platforms allow a local attacker to alter the behavior of the SPI flash potentially l…EPSS 0.34%5.6CVE-2018-3693Intel atom c vulnerabilitySystems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wi…EPSS 8.6%5.6CVE-2018-3640Intel atom c observable discrepancy vulnerabilitySystems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure…EPSS 7.6%

Source: NIST National Vulnerability Database (record CVE-2017-5715), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.