CVE-2022-23960
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
Published:Mar 8, 2022
Last Modified:Nov 21, 2024
EPS:Mar 12, 2022
EPSS Score:0.00143
CVSS Score:5.6
Affected Products
Vendor
Product
Action
Vendor
Arm
Product
Cortex-a57
Arm
Cortex-a57
Vendor
Arm
Product
Cortex-a57 Firmware
Arm
Cortex-a57 Firmware
Vendor
Arm
Product
Cortex-a65
Arm
Cortex-a65
Vendor
Arm
Product
Cortex-a65 Firmware
Arm
Cortex-a65 Firmware
Vendor
Arm
Product
Cortex-a65ae
Arm
Cortex-a65ae
Vendor
Arm
Product
Cortex-a65ae Firmware
Arm
Cortex-a65ae Firmware
Vendor
Arm
Product
Cortex-a710
Arm
Cortex-a710
Vendor
Arm
Product
Cortex-a710 Firmware
Arm
Cortex-a710 Firmware
Vendor
Arm
Product
Cortex-a72
Arm
Cortex-a72
Vendor
Arm
Product
Cortex-a72 Firmware
Arm
Cortex-a72 Firmware
Vendor
Arm
Product
Cortex-a73
Arm
Cortex-a73
Vendor
Arm
Product
Cortex-a73 Firmware
Arm
Cortex-a73 Firmware
Vendor
Arm
Product
Cortex-a75
Arm
Cortex-a75
Vendor
Arm
Product
Cortex-a75 Firmware
Arm
Cortex-a75 Firmware
Vendor
Arm
Product
Cortex-a76
Arm
Cortex-a76
Vendor
Arm
Product
Cortex-a76 Firmware
Arm
Cortex-a76 Firmware
Vendor
Arm
Product
Cortex-a76ae
Arm
Cortex-a76ae
Vendor
Arm
Product
Cortex-a76ae Firmware
Arm
Cortex-a76ae Firmware
Vendor
Arm
Product
Cortex-a77
Arm
Cortex-a77
Vendor
Arm
Product
Cortex-a77 Firmware
Arm
Cortex-a77 Firmware
Vendor
Arm
Product
Cortex-a78
Arm
Cortex-a78
Vendor
Arm
Product
Cortex-a78 Firmware
Arm
Cortex-a78 Firmware
Vendor
Arm
Product
Cortex-a78ae
Arm
Cortex-a78ae
Vendor
Arm
Product
Cortex-a78ae Firmware
Arm
Cortex-a78ae Firmware
Vendor
Arm
Product
Cortex-r7
Arm
Cortex-r7
Vendor
Arm
Product
Cortex-r7 Firmware
Arm
Cortex-r7 Firmware
Vendor
Arm
Product
Cortex-r8
Arm
Cortex-r8
Vendor
Arm
Product
Cortex-r8 Firmware
Arm
Cortex-r8 Firmware
Vendor
Arm
Product
Cortex-x1
Arm
Cortex-x1
Vendor
Arm
Product
Cortex-x1 Firmware
Arm
Cortex-x1 Firmware
Vendor
Arm
Product
Cortex-x2
Arm
Cortex-x2
Vendor
Arm
Product
Cortex-x2 Firmware
Arm
Cortex-x2 Firmware
Vendor
Arm
Product
Neoverse-e1
Arm
Neoverse-e1
Vendor
Arm
Product
Neoverse-e1 Firmware
Arm
Neoverse-e1 Firmware
Vendor
Arm
Product
Neoverse-v1
Arm
Neoverse-v1
Vendor
Arm
Product
Neoverse-v1 Firmware
Arm
Neoverse-v1 Firmware
Vendor
Arm
Product
Neoverse N1
Arm
Neoverse N1
Vendor
Arm
Product
Neoverse N1 Firmware
Arm
Neoverse N1 Firmware
Vendor
Arm
Product
Neoverse N2
Arm
Neoverse N2
Vendor
Arm
Product
Neoverse N2 Firmware
Arm
Neoverse N2 Firmware
Vendor
Debian
Product
Debian Linux
Debian
Debian Linux
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Rhel Eus
Redhat
Rhel Eus
Vendor
Redhat
Product
Rhev Hypervisor
Redhat
Rhev Hypervisor
Vendor
Xen
Product
Xen
Xen
Xen
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
