CVE-2018-3693

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.

Published: 2018-07-10 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2018-3693 is rated Moderate Risk (60.4/100): CVSS Medium severity, with high exploitation likelihood (EPSS 8.42%, 94th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +7.11% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2018-3693

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 1.31% 8.42% +7.11%
2 2026-06-12 0.96% 1.31% +0.34%
3 2026-06-02 0.96%

Full EPSS history (22 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2018-3693

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.6 3.1 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
1.1 4.0 [email protected]
4.7 2.0 MEDIUM
AV:L/AC:M/Au:N/C:C/I:N/A:N Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
3.4 6.9 [email protected]

Weakness enumeration for CVE-2018-3693

OS Trackers for CVE-2018-3693

vendor priority summary link
debian not yet assigned CVE-2018-3693 not yet assigned priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2018-3693
redhat high https://access.redhat.com/security/cve/CVE-2018-3693
suse high CVE-2018-3693 severity important: SUSE including 19 source package names (kernel-3.10.0-862.11.6.el7, kernel-abi-whitelists-3.10.0-862.11.6.el7, …), 78 product×package rows across 23 product lines (SUSE CaaS Platform 4.5, SUSE Enterprise Storage 7, … (23 product lines)): Known Not Affected 66, Fixed 12. https://www.suse.com/security/cve/CVE-2018-3693/
ubuntu high CVE-2018-3693 high priority: Ubuntu including 79 source packages (firefox, intel-microcode, …), 665 status rows across 11 suites (artful, bionic, cosmic, disco, focal, jammy, noble, oracular, trusty, upstream, xenial): DNE 414, not-affected 140, released 97, ignored 14. https://ubuntu.com/security/CVE-2018-3693

Affected software / configurations for CVE-2018-3693

Vendor Product Version Raw CPE
intel atom_c c2308 cpe:2.3:h:intel:atom_c:c2308:*:*:*:*:*:*:*
intel atom_c c2316 cpe:2.3:h:intel:atom_c:c2316:*:*:*:*:*:*:*
intel atom_c c2338 cpe:2.3:h:intel:atom_c:c2338:*:*:*:*:*:*:*
intel atom_c c2350 cpe:2.3:h:intel:atom_c:c2350:*:*:*:*:*:*:*
intel atom_c c2358 cpe:2.3:h:intel:atom_c:c2358:*:*:*:*:*:*:*
intel atom_c c2508 cpe:2.3:h:intel:atom_c:c2508:*:*:*:*:*:*:*
intel atom_c c2516 cpe:2.3:h:intel:atom_c:c2516:*:*:*:*:*:*:*
intel atom_c c2518 cpe:2.3:h:intel:atom_c:c2518:*:*:*:*:*:*:*
intel atom_c c2530 cpe:2.3:h:intel:atom_c:c2530:*:*:*:*:*:*:*
intel atom_c c2538 cpe:2.3:h:intel:atom_c:c2538:*:*:*:*:*:*:*
intel atom_c c2550 cpe:2.3:h:intel:atom_c:c2550:*:*:*:*:*:*:*
intel atom_c c2558 cpe:2.3:h:intel:atom_c:c2558:*:*:*:*:*:*:*
intel atom_c c2718 cpe:2.3:h:intel:atom_c:c2718:*:*:*:*:*:*:*
intel atom_c c2730 cpe:2.3:h:intel:atom_c:c2730:*:*:*:*:*:*:*
intel atom_c c2738 cpe:2.3:h:intel:atom_c:c2738:*:*:*:*:*:*:*
intel atom_c c2750 cpe:2.3:h:intel:atom_c:c2750:*:*:*:*:*:*:*
intel atom_c c2758 cpe:2.3:h:intel:atom_c:c2758:*:*:*:*:*:*:*
intel atom_c c3308 cpe:2.3:h:intel:atom_c:c3308:*:*:*:*:*:*:*
intel atom_c c3338 cpe:2.3:h:intel:atom_c:c3338:*:*:*:*:*:*:*
intel atom_c c3508 cpe:2.3:h:intel:atom_c:c3508:*:*:*:*:*:*:*
intel atom_c c3538 cpe:2.3:h:intel:atom_c:c3538:*:*:*:*:*:*:*
intel atom_c c3558 cpe:2.3:h:intel:atom_c:c3558:*:*:*:*:*:*:*
intel atom_c c3708 cpe:2.3:h:intel:atom_c:c3708:*:*:*:*:*:*:*
intel atom_c c3750 cpe:2.3:h:intel:atom_c:c3750:*:*:*:*:*:*:*
intel atom_c c3758 cpe:2.3:h:intel:atom_c:c3758:*:*:*:*:*:*:*
intel atom_c c3808 cpe:2.3:h:intel:atom_c:c3808:*:*:*:*:*:*:*
intel atom_c c3830 cpe:2.3:h:intel:atom_c:c3830:*:*:*:*:*:*:*
intel atom_c c3850 cpe:2.3:h:intel:atom_c:c3850:*:*:*:*:*:*:*
intel atom_c c3858 cpe:2.3:h:intel:atom_c:c3858:*:*:*:*:*:*:*
intel atom_c c3950 cpe:2.3:h:intel:atom_c:c3950:*:*:*:*:*:*:*
intel atom_c c3955 cpe:2.3:h:intel:atom_c:c3955:*:*:*:*:*:*:*
intel atom_c c3958 cpe:2.3:h:intel:atom_c:c3958:*:*:*:*:*:*:*
intel atom_e e3805 cpe:2.3:h:intel:atom_e:e3805:*:*:*:*:*:*:*
intel atom_e e3815 cpe:2.3:h:intel:atom_e:e3815:*:*:*:*:*:*:*
intel atom_e e3825 cpe:2.3:h:intel:atom_e:e3825:*:*:*:*:*:*:*
intel atom_e e3826 cpe:2.3:h:intel:atom_e:e3826:*:*:*:*:*:*:*
intel atom_e e3827 cpe:2.3:h:intel:atom_e:e3827:*:*:*:*:*:*:*
intel atom_e e3845 cpe:2.3:h:intel:atom_e:e3845:*:*:*:*:*:*:*
intel atom_x3 c3130 cpe:2.3:h:intel:atom_x3:c3130:*:*:*:*:*:*:*
intel atom_x3 c3200rk cpe:2.3:h:intel:atom_x3:c3200rk:*:*:*:*:*:*:*
intel atom_x3 c3205rk cpe:2.3:h:intel:atom_x3:c3205rk:*:*:*:*:*:*:*
intel atom_x3 c3230rk cpe:2.3:h:intel:atom_x3:c3230rk:*:*:*:*:*:*:*
intel atom_x3 c3235rk cpe:2.3:h:intel:atom_x3:c3235rk:*:*:*:*:*:*:*
intel atom_x3 c3265rk cpe:2.3:h:intel:atom_x3:c3265rk:*:*:*:*:*:*:*
intel atom_x3 c3295rk cpe:2.3:h:intel:atom_x3:c3295rk:*:*:*:*:*:*:*
intel atom_x3 c3405 cpe:2.3:h:intel:atom_x3:c3405:*:*:*:*:*:*:*
intel atom_x3 c3445 cpe:2.3:h:intel:atom_x3:c3445:*:*:*:*:*:*:*
intel atom_z z2420 cpe:2.3:h:intel:atom_z:z2420:*:*:*:*:*:*:*
intel atom_z z2460 cpe:2.3:h:intel:atom_z:z2460:*:*:*:*:*:*:*
intel atom_z z2480 cpe:2.3:h:intel:atom_z:z2480:*:*:*:*:*:*:*
intel atom_z z2520 cpe:2.3:h:intel:atom_z:z2520:*:*:*:*:*:*:*
intel atom_z z2560 cpe:2.3:h:intel:atom_z:z2560:*:*:*:*:*:*:*
intel atom_z z2580 cpe:2.3:h:intel:atom_z:z2580:*:*:*:*:*:*:*
intel atom_z z2760 cpe:2.3:h:intel:atom_z:z2760:*:*:*:*:*:*:*
intel atom_z z3460 cpe:2.3:h:intel:atom_z:z3460:*:*:*:*:*:*:*
intel atom_z z3480 cpe:2.3:h:intel:atom_z:z3480:*:*:*:*:*:*:*
intel atom_z z3530 cpe:2.3:h:intel:atom_z:z3530:*:*:*:*:*:*:*
intel atom_z z3560 cpe:2.3:h:intel:atom_z:z3560:*:*:*:*:*:*:*
intel atom_z z3570 cpe:2.3:h:intel:atom_z:z3570:*:*:*:*:*:*:*
intel atom_z z3580 cpe:2.3:h:intel:atom_z:z3580:*:*:*:*:*:*:*
intel atom_z z3590 cpe:2.3:h:intel:atom_z:z3590:*:*:*:*:*:*:*
intel atom_z z3735d cpe:2.3:h:intel:atom_z:z3735d:*:*:*:*:*:*:*
intel atom_z z3735e cpe:2.3:h:intel:atom_z:z3735e:*:*:*:*:*:*:*
intel atom_z z3735f cpe:2.3:h:intel:atom_z:z3735f:*:*:*:*:*:*:*
intel atom_z z3735g cpe:2.3:h:intel:atom_z:z3735g:*:*:*:*:*:*:*
intel atom_z z3736f cpe:2.3:h:intel:atom_z:z3736f:*:*:*:*:*:*:*
intel atom_z z3736g cpe:2.3:h:intel:atom_z:z3736g:*:*:*:*:*:*:*
intel atom_z z3740 cpe:2.3:h:intel:atom_z:z3740:*:*:*:*:*:*:*
intel atom_z z3740d cpe:2.3:h:intel:atom_z:z3740d:*:*:*:*:*:*:*
intel atom_z z3745 cpe:2.3:h:intel:atom_z:z3745:*:*:*:*:*:*:*
intel atom_z z3745d cpe:2.3:h:intel:atom_z:z3745d:*:*:*:*:*:*:*
intel atom_z z3770 cpe:2.3:h:intel:atom_z:z3770:*:*:*:*:*:*:*
intel atom_z z3770d cpe:2.3:h:intel:atom_z:z3770d:*:*:*:*:*:*:*
intel atom_z z3775 cpe:2.3:h:intel:atom_z:z3775:*:*:*:*:*:*:*
intel atom_z z3775d cpe:2.3:h:intel:atom_z:z3775d:*:*:*:*:*:*:*
intel atom_z z3785 cpe:2.3:h:intel:atom_z:z3785:*:*:*:*:*:*:*
intel atom_z z3795 cpe:2.3:h:intel:atom_z:z3795:*:*:*:*:*:*:*
intel celeron_j j1750 cpe:2.3:h:intel:celeron_j:j1750:*:*:*:*:*:*:*
intel celeron_j j1800 cpe:2.3:h:intel:celeron_j:j1800:*:*:*:*:*:*:*
intel celeron_j j1850 cpe:2.3:h:intel:celeron_j:j1850:*:*:*:*:*:*:*

References for CVE-2018-3693

URL Tags
https://access.redhat.com/errata/RHSA-2018:2384 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2390 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2395 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1946 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0174 Third Party Advisory
https://cdrdv2.intel.com/v1/dl/getContent/685359 Third Party Advisory
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 Third Party Advisory
https://security.netapp.com/advisory/ntap-20180823-0001/ Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html Patch Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html Patch Third Party Advisory
cvelogic Threat Intelligence