Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Loading...
Loading...
Score elevated to 9.0 because EPSS predicts 89% probability of exploitation within the next 30 days (top 0.5% of all CVEs). NVD baseline CVSS 5.6 retained for reference. Confidence: see factors.
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
January 4, 2018
May 6, 2025
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
RHBA-2018:0042 — Important
RHBA-2018:0831 — Important
RHEA-2018:0690 — Important
RHEA-2018:0704 — Important
RHEA-2018:0874 — Important
RHSA-2018:0016 — Important
RHSA-2018:0017 — Important
RHSA-2018:0018 — Important
RHSA-2018:0020 — Important
RHSA-2018:0021 — Important
RHSA-2018:0022 — Important
RHSA-2018:0023 — Important
RHSA-2018:0027 — Important
RHSA-2018:0028 — Important
RHSA-2018:1062 — Important
RHSA-2018:1129 — Important
RHSA-2018:1130 — Important
RHSA-2018:1196 — Important
RHSA-2018:1216 — Important
RHSA-2018:1252 — Important
RHSA-2018:1319 — Important
RHSA-2018:1346 — Important
Firefox vulnerabilities
WebKitGTK+ vulnerabilities
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (2 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
a list of BIOS/Firmware fixes adressing CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
Open source ↗Spectre exploit
Open source ↗Multiple CPUs - 'Spectre' Information Disclosure
Open source ↗This CVE was central to one or more publicly-documented breaches. Each card links to authoritative reporting at the time of the incident.
Speculative-execution side-channel attacks against virtually every modern CPU (Intel, AMD, ARM). Required hardware-firmware updates and OS kernel changes across the industry.
Source: ZDNetSee which npm, PyPI, Go, and Maven packages are affected by CVE-2017-5715
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
redhat
CWE-203