« Volver al listado

CVE-2017-5926

Estado: ModificadaAlta (7.5)—

Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (20)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-5926",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-02-27T07:59:00.207",
  "references": [
    {
      "url": "http://www.cs.vu.nl/~herbertb/download/papers/anc_ndss17.pdf",
      "tags": [
        "Exploit",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/96457",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.vusec.net/projects/anc",
      "tags": [
        "Exploit",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.cs.vu.nl/~herbertb/download/papers/anc_ndss17.pdf",
      "tags": [
        "Exploit",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/96457",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.vusec.net/projects/anc",
      "tags": [
        "Exploit",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR."
    },
    {
      "lang": "es",
      "value": "Los paseos de la tabla de páginas llevados a cabo por la MMU durante la traducción de la dirección virtual a física dejan un rastro en la caché de último nivel de los procesadores AMD modernos. Realizando un ataque de canal lateral en las operaciones de MMU, es posible perder datos y punteros de código de JavaScript, rompiendo la ASLR."
    }
  ],
  "lastModified": "2026-06-17T01:21:26.783",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:allwinner:a64:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E8167A6-98BE-45D9-A333-A4DB8EE9BE43"
            },
            {
              "criteria": "cpe:2.3:h:amd:athlon_ii_640_x4:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4355B92A-F9A4-4DA0-9875-B0D8BD5541AC"
            },
            {
              "criteria": "cpe:2.3:h:amd:e-350:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF28E516-87C3-48BF-ADCB-E89C41DB3E4C"
            },
            {
              "criteria": "cpe:2.3:h:amd:fx-8120_8-core:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53A9CAF2-DABC-4DD0-87B3-552C469835CC"
            },
            {
              "criteria": "cpe:2.3:h:amd:fx-8320_8-core:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5AC0369B-FB5E-48DF-B1E5-72BAD0A0CDEA"
            },
            {
              "criteria": "cpe:2.3:h:amd:fx-8350_8-core:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8519A289-6ADE-415A-AE6A-33FD68AFBDCE"
            },
            {
              "criteria": "cpe:2.3:h:amd:phenom_9550_4-core:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B51CAD25-267C-4BF2-B738-25B213FCDFD0"
            },
            {
              "criteria": "cpe:2.3:h:intel:atom_c2750:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59CD7DDA-6DDA-47CF-9A75-AFA75B02A56F"
            },
            {
              "criteria": "cpe:2.3:h:intel:celeron_n2840:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3826FEBA-0B2E-403D-9A6A-0DA02FEF9A2B"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i5_m480:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E92B12C0-E86A-44A0-B302-3CE721237726"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i7-2620qm:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A3B3752-79A3-45A8-8416-6DC1EA4A9E81"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i7-3632qm:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09B0D125-332D-416D-A379-F0D7C1F9DA27"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i7-4500u:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "677C66EF-E9B9-430F-A19D-2D87AD83DBDB"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i7-6700k:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EAFC55E4-D84D-4588-976D-1E2637B1BF0E"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i7_920:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FF0E91E0-F4B0-495A-80BA-B6B05E6F1760"
            },
            {
              "criteria": "cpe:2.3:h:intel:xeon_e3-1240_v5:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51E0227B-8F2B-48B3-97BC-73BA1BACEED8"
            },
            {
              "criteria": "cpe:2.3:h:intel:xeon_e5-2658_v2:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "661C05F6-8659-4C06-8AC5-7A25FFA52C2A"
            },
            {
              "criteria": "cpe:2.3:h:nvidia:tegra_k1_cd570m-a1:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C57EA6EC-A6B2-4A6A-A13C-EA86154DCA0C"
            },
            {
              "criteria": "cpe:2.3:h:nvidia:tegra_k1_cd580m-a1:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA4020D9-99C1-4366-8377-8DD1A983381A"
            },
            {
              "criteria": "cpe:2.3:h:samsung:exynos_5800:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36182055-4545-405C-8B39-CF5B87C014C7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}