← Vulnerability feed

Vulnerability record · CVE-2022-38090 · published 16 February 2023

CVE-2022-38090: Intel xeon gold 5315y firmware vulnerability

Intel · Xeon Gold 5315y Firmware

Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.

4.4 CVSS 3.1 Medium EPSS 0.25% · top 85.2% CWE-922 · CWE-922
4.4CVSS 3.1 base score
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-38090 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.0CVE-2022-44611Intel celeron j6413 firmware improper input validation vulnerabilityImproper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege…EPSS 0.35%7.8CVE-2021-33122Intel xeon e-2386g firmware vulnerabilityInsufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation …EPSS 0.26%7.8CVE-2019-0155Redhat enterprise linux server aus vulnerabilityInsufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;…EPSS 0.67%6.7CVE-2021-33103Intel xeon e-2386g firmware vulnerabilityUnintended intermediary in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalat…EPSS 0.26%6.5CVE-2022-40982Redhat enterprise linux observable discrepancy vulnerabilityInformation exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may al…EPSS 3.0%6.5CVE-2018-12207Intel core i3-10110u firmware improper input validation vulnerabilityImproper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to …EPSS 0.92%2.4CVE-2022-0005Intel celeron g5205u firmware cleartext transmission vulnerabilitySensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to potent…EPSS 0.21%

Source: NIST National Vulnerability Database (record CVE-2022-38090), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.