2023-10-04 06:00:28 +00:00
{
"id" : "CVE-2023-5370" ,
"sourceIdentifier" : "secteam@freebsd.org" ,
"published" : "2023-10-04T04:15:15.593" ,
2024-03-07 12:27:24 +00:00
"lastModified" : "2023-11-24T09:15:09.677" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-10-04 06:00:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no speculative execution workarounds being installed on CPU 0."
2023-10-04 14:00:28 +00:00
} ,
{
"lang" : "es" ,
"value" : "En la CPU 0, se llama a la verificaci\u00f3n del workaround de SMCCC antes de que se haya inicializado el soporte de SMCCC. Esto result\u00f3 en que no se instalaran workarounds de ejecuci\u00f3n especulativa en la CPU 0."
2023-10-04 06:00:28 +00:00
}
] ,
2023-10-10 16:00:28 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.5 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 3.6
}
]
} ,
2023-10-04 06:00:28 +00:00
"weaknesses" : [
2023-10-10 16:00:28 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-665"
}
]
} ,
2023-10-04 06:00:28 +00:00
{
"source" : "secteam@freebsd.org" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-665"
}
]
}
] ,
2023-10-10 16:00:28 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:freebsd:freebsd:13.2:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "A87EFA20-DD6B-41C5-98FD-A29F67D2E732"
}
]
}
]
}
] ,
2023-10-04 06:00:28 +00:00
"references" : [
{
"url" : "https://security.FreeBSD.org/advisories/FreeBSD-SA-23:14.smccc.asc" ,
2023-10-10 16:00:28 +00:00
"source" : "secteam@freebsd.org" ,
"tags" : [
"Vendor Advisory"
]
2024-03-07 12:27:24 +00:00
} ,
{
"url" : "https://security.netapp.com/advisory/ntap-20231124-0005/" ,
"source" : "secteam@freebsd.org"
2023-10-04 06:00:28 +00:00
}
]
}