CVE-2017-5715

Exp

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

Published: 2018-01-04 Last update: 2025-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2017-5715 is rated High Exploit Risk (72.1/100): CVSS Medium severity, with high exploitation likelihood (EPSS 88.48%, 100th percentile). Core evidence: 3 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2017-5715

EDB-ID Source Kind Published Link
43427 exploit_db edb 2018-01-03 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2017-5715

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-05 88.60% 88.48% -0.11%
2 2026-05-23 88.42% 88.60% +0.17%
3 2026-05-22 88.42%

Full EPSS history (76 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2017-5715

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.6 3.1 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
1.1 4.0 [email protected]
5.6 3.1 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
1.1 4.0 134c704f-9b21-4f2e-91b3-4a467353bcc0
1.9 2.0 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
3.4 2.9 [email protected]

Weakness enumeration for CVE-2017-5715

OS Trackers for CVE-2017-5715

vendor priority summary link
debian not yet assigned CVE-2017-5715 not yet assigned priority: Debian including 8 source packages (amd64-microcode, intel-microcode, …), 32 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 32. https://security-tracker.debian.org/tracker/CVE-2017-5715
gentoo normal CVE-2017-5715: 2 GLSA(s) (201804-08, 201810-06), 3 atom(s) (app-emulation/qemu, app-emulation/xen, app-emulation/xen-tools); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2017-5715
redhat high https://access.redhat.com/security/cve/CVE-2017-5715
suse high CVE-2017-5715 severity important: SUSE including 2923 source package names (WebKit2GTK-4.1-lang-2.36.0-150400.2.13, WebKit2GTK-5.0-lang-2.36.0-150400.2.12, …), 4430 product×package rows across 165 product lines (Image SLES12-SP4-SAP-Azure-LI-BYOS-Production, Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production, … (165 product lines)): Fixed 3890, Known Not Affected 383, Known Affected 157. https://www.suse.com/security/cve/CVE-2017-5715/
ubuntu high CVE-2017-5715 high priority: Ubuntu including 87 source packages (amd64-microcode, firefox, …), 770 status rows across 12 suites (artful, bionic, cosmic, disco, focal, jammy, noble, oracular, trusty, upstream, xenial, zesty): DNE 461, not-affected 159, released 128, ignored 17, needs-triage 5. https://ubuntu.com/security/CVE-2017-5715

Affected software / configurations for CVE-2017-5715

Vendor Product Version Raw CPE
intel atom_c c2308 cpe:2.3:h:intel:atom_c:c2308:*:*:*:*:*:*:*
intel atom_c c2316 cpe:2.3:h:intel:atom_c:c2316:*:*:*:*:*:*:*
intel atom_c c2338 cpe:2.3:h:intel:atom_c:c2338:*:*:*:*:*:*:*
intel atom_c c2350 cpe:2.3:h:intel:atom_c:c2350:*:*:*:*:*:*:*
intel atom_c c2358 cpe:2.3:h:intel:atom_c:c2358:*:*:*:*:*:*:*
intel atom_c c2508 cpe:2.3:h:intel:atom_c:c2508:*:*:*:*:*:*:*
intel atom_c c2516 cpe:2.3:h:intel:atom_c:c2516:*:*:*:*:*:*:*
intel atom_c c2518 cpe:2.3:h:intel:atom_c:c2518:*:*:*:*:*:*:*
intel atom_c c2530 cpe:2.3:h:intel:atom_c:c2530:*:*:*:*:*:*:*
intel atom_c c2538 cpe:2.3:h:intel:atom_c:c2538:*:*:*:*:*:*:*
intel atom_c c2550 cpe:2.3:h:intel:atom_c:c2550:*:*:*:*:*:*:*
intel atom_c c2558 cpe:2.3:h:intel:atom_c:c2558:*:*:*:*:*:*:*
intel atom_c c2718 cpe:2.3:h:intel:atom_c:c2718:*:*:*:*:*:*:*
intel atom_c c2730 cpe:2.3:h:intel:atom_c:c2730:*:*:*:*:*:*:*
intel atom_c c2738 cpe:2.3:h:intel:atom_c:c2738:*:*:*:*:*:*:*
intel atom_c c2750 cpe:2.3:h:intel:atom_c:c2750:*:*:*:*:*:*:*
intel atom_c c2758 cpe:2.3:h:intel:atom_c:c2758:*:*:*:*:*:*:*
intel atom_c c3308 cpe:2.3:h:intel:atom_c:c3308:*:*:*:*:*:*:*
intel atom_c c3338 cpe:2.3:h:intel:atom_c:c3338:*:*:*:*:*:*:*
intel atom_c c3508 cpe:2.3:h:intel:atom_c:c3508:*:*:*:*:*:*:*
intel atom_c c3538 cpe:2.3:h:intel:atom_c:c3538:*:*:*:*:*:*:*
intel atom_c c3558 cpe:2.3:h:intel:atom_c:c3558:*:*:*:*:*:*:*
intel atom_c c3708 cpe:2.3:h:intel:atom_c:c3708:*:*:*:*:*:*:*
intel atom_c c3750 cpe:2.3:h:intel:atom_c:c3750:*:*:*:*:*:*:*
intel atom_c c3758 cpe:2.3:h:intel:atom_c:c3758:*:*:*:*:*:*:*
intel atom_c c3808 cpe:2.3:h:intel:atom_c:c3808:*:*:*:*:*:*:*
intel atom_c c3830 cpe:2.3:h:intel:atom_c:c3830:*:*:*:*:*:*:*
intel atom_c c3850 cpe:2.3:h:intel:atom_c:c3850:*:*:*:*:*:*:*
intel atom_c c3858 cpe:2.3:h:intel:atom_c:c3858:*:*:*:*:*:*:*
intel atom_c c3950 cpe:2.3:h:intel:atom_c:c3950:*:*:*:*:*:*:*
intel atom_c c3955 cpe:2.3:h:intel:atom_c:c3955:*:*:*:*:*:*:*
intel atom_c c3958 cpe:2.3:h:intel:atom_c:c3958:*:*:*:*:*:*:*
intel atom_e e3805 cpe:2.3:h:intel:atom_e:e3805:*:*:*:*:*:*:*
intel atom_e e3815 cpe:2.3:h:intel:atom_e:e3815:*:*:*:*:*:*:*
intel atom_e e3825 cpe:2.3:h:intel:atom_e:e3825:*:*:*:*:*:*:*
intel atom_e e3826 cpe:2.3:h:intel:atom_e:e3826:*:*:*:*:*:*:*
intel atom_e e3827 cpe:2.3:h:intel:atom_e:e3827:*:*:*:*:*:*:*
intel atom_e e3845 cpe:2.3:h:intel:atom_e:e3845:*:*:*:*:*:*:*
intel atom_x3 c3130 cpe:2.3:h:intel:atom_x3:c3130:*:*:*:*:*:*:*
intel atom_x3 c3200rk cpe:2.3:h:intel:atom_x3:c3200rk:*:*:*:*:*:*:*
intel atom_x3 c3205rk cpe:2.3:h:intel:atom_x3:c3205rk:*:*:*:*:*:*:*
intel atom_x3 c3230rk cpe:2.3:h:intel:atom_x3:c3230rk:*:*:*:*:*:*:*
intel atom_x3 c3235rk cpe:2.3:h:intel:atom_x3:c3235rk:*:*:*:*:*:*:*
intel atom_x3 c3265rk cpe:2.3:h:intel:atom_x3:c3265rk:*:*:*:*:*:*:*
intel atom_x3 c3295rk cpe:2.3:h:intel:atom_x3:c3295rk:*:*:*:*:*:*:*
intel atom_x3 c3405 cpe:2.3:h:intel:atom_x3:c3405:*:*:*:*:*:*:*
intel atom_x3 c3445 cpe:2.3:h:intel:atom_x3:c3445:*:*:*:*:*:*:*
intel atom_x5-e3930 cpe:2.3:h:intel:atom_x5-e3930:-:*:*:*:*:*:*:*
intel atom_x5-e3940 cpe:2.3:h:intel:atom_x5-e3940:-:*:*:*:*:*:*:*
intel atom_x7-e3950 cpe:2.3:h:intel:atom_x7-e3950:-:*:*:*:*:*:*:*
intel atom_z z2420 cpe:2.3:h:intel:atom_z:z2420:*:*:*:*:*:*:*
intel atom_z z2460 cpe:2.3:h:intel:atom_z:z2460:*:*:*:*:*:*:*
intel atom_z z2480 cpe:2.3:h:intel:atom_z:z2480:*:*:*:*:*:*:*
intel atom_z z2520 cpe:2.3:h:intel:atom_z:z2520:*:*:*:*:*:*:*
intel atom_z z2560 cpe:2.3:h:intel:atom_z:z2560:*:*:*:*:*:*:*
intel atom_z z2580 cpe:2.3:h:intel:atom_z:z2580:*:*:*:*:*:*:*
intel atom_z z2760 cpe:2.3:h:intel:atom_z:z2760:*:*:*:*:*:*:*
intel atom_z z3460 cpe:2.3:h:intel:atom_z:z3460:*:*:*:*:*:*:*
intel atom_z z3480 cpe:2.3:h:intel:atom_z:z3480:*:*:*:*:*:*:*
intel atom_z z3530 cpe:2.3:h:intel:atom_z:z3530:*:*:*:*:*:*:*
intel atom_z z3560 cpe:2.3:h:intel:atom_z:z3560:*:*:*:*:*:*:*
intel atom_z z3570 cpe:2.3:h:intel:atom_z:z3570:*:*:*:*:*:*:*
intel atom_z z3580 cpe:2.3:h:intel:atom_z:z3580:*:*:*:*:*:*:*
intel atom_z z3590 cpe:2.3:h:intel:atom_z:z3590:*:*:*:*:*:*:*
intel atom_z z3735d cpe:2.3:h:intel:atom_z:z3735d:*:*:*:*:*:*:*
intel atom_z z3735e cpe:2.3:h:intel:atom_z:z3735e:*:*:*:*:*:*:*
intel atom_z z3735f cpe:2.3:h:intel:atom_z:z3735f:*:*:*:*:*:*:*
intel atom_z z3735g cpe:2.3:h:intel:atom_z:z3735g:*:*:*:*:*:*:*
intel atom_z z3736f cpe:2.3:h:intel:atom_z:z3736f:*:*:*:*:*:*:*
intel atom_z z3736g cpe:2.3:h:intel:atom_z:z3736g:*:*:*:*:*:*:*
intel atom_z z3740 cpe:2.3:h:intel:atom_z:z3740:*:*:*:*:*:*:*
intel atom_z z3740d cpe:2.3:h:intel:atom_z:z3740d:*:*:*:*:*:*:*
intel atom_z z3745 cpe:2.3:h:intel:atom_z:z3745:*:*:*:*:*:*:*
intel atom_z z3745d cpe:2.3:h:intel:atom_z:z3745d:*:*:*:*:*:*:*
intel atom_z z3770 cpe:2.3:h:intel:atom_z:z3770:*:*:*:*:*:*:*
intel atom_z z3770d cpe:2.3:h:intel:atom_z:z3770d:*:*:*:*:*:*:*
intel atom_z z3775 cpe:2.3:h:intel:atom_z:z3775:*:*:*:*:*:*:*
intel atom_z z3775d cpe:2.3:h:intel:atom_z:z3775d:*:*:*:*:*:*:*
intel atom_z z3785 cpe:2.3:h:intel:atom_z:z3785:*:*:*:*:*:*:*
intel atom_z z3795 cpe:2.3:h:intel:atom_z:z3795:*:*:*:*:*:*:*

References for CVE-2017-5715

URL Tags
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00002.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00003.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00004.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00005.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00009.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00012.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00013.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html Broken Link
http://nvidia.custhelp.com/app/answers/detail/a_id/4609 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4611 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4613 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4614 Third Party Advisory
http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.html Third Party Advisory VDB Entry
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt Third Party Advisory
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt Third Party Advisory
http://www.kb.cert.org/vuls/id/584653 Third Party Advisory US Government Resource
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html Third Party Advisory
http://www.securityfocus.com/bid/102376 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040071 Third Party Advisory VDB Entry
http://xenbits.xen.org/xsa/advisory-254.html Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0292 Third Party Advisory
https://access.redhat.com/security/vulnerabilities/speculativeexecution Third Party Advisory
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ Third Party Advisory
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf Third Party Advisory
https://cert.vde.com/en-us/advisories/vde-2018-002 Third Party Advisory
https://cert.vde.com/en-us/advisories/vde-2018-003 Third Party Advisory
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability Third Party Advisory
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html Third Party Advisory
https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00015.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00016.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/09/msg00017.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/03/msg00025.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/08/msg00019.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 Patch Third Party Advisory Vendor Advisory
https://seclists.org/bugtraq/2019/Jun/36 Issue Tracking Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Nov/16 Issue Tracking Mailing List Third Party Advisory
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00088&languageid=en-fr Vendor Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-18:03.speculative_execution.asc Third Party Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-19:26.mcu.asc Third Party Advisory
https://security.gentoo.org/glsa/201810-06 Third Party Advisory
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html Third Party Advisory
https://security.netapp.com/advisory/ntap-20180104-0001/ Third Party Advisory
https://security.paloaltonetworks.com/CVE-2017-5715 Third Party Advisory
https://spectreattack.com/ Third Party Advisory
https://support.citrix.com/article/CTX231399 Third Party Advisory
https://support.f5.com/csp/article/K91229003 Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_us Third Party Advisory
https://support.lenovo.com/us/en/solutions/LEN-18282 Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannel Third Party Advisory
https://usn.ubuntu.com/3531-1/ Third Party Advisory
https://usn.ubuntu.com/3531-3/ Third Party Advisory
https://usn.ubuntu.com/3540-2/ Third Party Advisory
https://usn.ubuntu.com/3541-2/ Third Party Advisory
https://usn.ubuntu.com/3542-2/ Third Party Advisory
https://usn.ubuntu.com/3549-1/ Third Party Advisory
https://usn.ubuntu.com/3560-1/ Third Party Advisory
https://usn.ubuntu.com/3561-1/ Third Party Advisory
https://usn.ubuntu.com/3580-1/ Third Party Advisory
https://usn.ubuntu.com/3581-1/ Third Party Advisory
https://usn.ubuntu.com/3581-2/ Third Party Advisory
https://usn.ubuntu.com/3582-1/ Third Party Advisory
https://usn.ubuntu.com/3582-2/ Third Party Advisory
https://usn.ubuntu.com/3594-1/ Third Party Advisory
https://usn.ubuntu.com/3597-1/ Third Party Advisory
https://usn.ubuntu.com/3597-2/ Third Party Advisory
https://usn.ubuntu.com/3620-2/ Third Party Advisory
https://usn.ubuntu.com/3690-1/ Third Party Advisory
https://usn.ubuntu.com/3777-3/ Third Party Advisory
https://usn.ubuntu.com/usn/usn-3516-1/ Third Party Advisory
https://www.debian.org/security/2018/dsa-4120 Third Party Advisory
https://www.debian.org/security/2018/dsa-4187 Third Party Advisory
https://www.debian.org/security/2018/dsa-4188 Third Party Advisory
https://www.debian.org/security/2018/dsa-4213 Third Party Advisory
https://www.exploit-db.com/exploits/43427/ Exploit Third Party Advisory VDB Entry
https://www.kb.cert.org/vuls/id/180049 Third Party Advisory US Government Resource
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001 Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html Third Party Advisory
https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/ Third Party Advisory
https://www.synology.com/support/security/Synology_SA_18_01 Third Party Advisory
https://www.vmware.com/security/advisories/VMSA-2018-0007.html Third Party Advisory
https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html Third Party Advisory
https://www.vmware.com/us/security/advisories/VMSA-2018-0004.html Third Party Advisory
cvelogic Threat Intelligence