← Vulnerability feed

Vulnerability record · CVE-2018-3640 · published 22 May 2018

CVE-2018-3640: Intel atom c observable discrepancy vulnerability

Intel · Atom C

Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.

5.6 CVSS 3.0 Medium EPSS 7.6% · top 5.7% CWE-203 · Observable discrepancy
5.6CVSS 3.0 base score, v2 4.7
7.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
44References
17 Jun 2026Last modified by NVD

Description

Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://support.lenovo.com/us/en/solutions/LEN-22133 Third Party Advisory
http://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.html Third Party Advisory
http://www.securityfocus.com/bid/104228 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040949 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1042004
https://cert-portal.siemens.com/productcert/pdf/ssa-268644.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability Vendor Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00038.html
https://lists.debian.org/debian-lts-announce/2018/09/msg00017.html
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV180013 PatchThird Party AdvisoryVendor Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0005
https://security.netapp.com/advisory/ntap-20180521-0001/ Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03850en_us Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180521-cpusidechannel Third Party Advisory
https://usn.ubuntu.com/3756-1/
https://www.debian.org/security/2018/dsa-4273
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.html Vendor Advisory
https://www.kb.cert.org/vuls/id/180049 Third Party AdvisoryUS Government Resource
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0006
https://www.synology.com/support/security/Synology_SA_18_23 Third Party Advisory
https://www.us-cert.gov/ncas/alerts/TA18-141A Third Party AdvisoryUS Government Resource
http://support.lenovo.com/us/en/solutions/LEN-22133 Third Party Advisory
http://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.html Third Party Advisory
http://www.securityfocus.com/bid/104228 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040949 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1042004
https://cert-portal.siemens.com/productcert/pdf/ssa-268644.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability Vendor Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00038.html
https://lists.debian.org/debian-lts-announce/2018/09/msg00017.html
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV180013 PatchThird Party AdvisoryVendor Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0005
https://security.netapp.com/advisory/ntap-20180521-0001/ Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03850en_us Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180521-cpusidechannel Third Party Advisory
https://usn.ubuntu.com/3756-1/
https://www.debian.org/security/2018/dsa-4273
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.html Vendor Advisory

Track CVE-2018-3640 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.6CVE-2018-3652Intel xeon e3 information exposure vulnerabilityExisting UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable p…EPSS 0.37%5.6CVE-2018-3693Intel atom c vulnerabilitySystems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wi…EPSS 8.6%5.6CVE-2018-9056Intel atom c information exposure vulnerabilitySystems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access v…EPSS 0.67%5.6CVE-2017-5715Intel CPUs speculative execution side-channel information disclosureCVE-2017-5715 is the Spectre variant 2 flaw in Intel microprocessors that use speculative execution and indirect branch prediction. A local attacker …EPSS 74%analysed5.6CVE-2017-5753Intel CPUs speculative execution side-channel information disclosure (Spectre v1)CVE-2017-5753 is a speculative execution and branch prediction side-channel flaw in Intel microprocessors that can leak information through observabl…EPSS 94%analysed5.6CVE-2017-5754Intel CPUs speculative execution side-channel information disclosureIntel microprocessors using speculative execution and indirect branch prediction can leak data through a side-channel analysis of the data cache. A l…EPSS 84%analysed5.5CVE-2019-14615Canonical ubuntu linux vulnerabilityInsufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user …EPSS 1.4%5.5CVE-2018-3639Intel microprocessors speculative store bypass side-channel info disclosureCVE-2018-3639 is the Speculative Store Bypass (SSB) side-channel flaw, also called Variant 4, affecting Intel microprocessors that use speculative ex…EPSS 61%analysed

Source: NIST National Vulnerability Database (record CVE-2018-3640), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.