CVE Feed

    Dashboard / CVE / CVE-2022-48251

    CVE-2022-48251

    The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not directly caused by or related to the Arm architecture."

    Published:Jan 10, 2023
    Last Modified:Nov 21, 2024
    EPS:Jan 10, 2023
    EPSS Score:0.00115
    CVSS Score:7.5

    Affected Products

    Vendor
    Arm
    Product
    Cortex-a53
    Vendor
    Arm
    Product
    Cortex-a53 Firmware
    Vendor
    Arm
    Product
    Cortex-a55
    Vendor
    Arm
    Product
    Cortex-a55 Firmware
    Vendor
    Arm
    Product
    Cortex-a57
    Vendor
    Arm
    Product
    Cortex-a57 Firmware
    Vendor
    Arm
    Product
    Cortex-a72
    Vendor
    Arm
    Product
    Cortex-a72 Firmware
    Vendor
    Arm
    Product
    Cortex-a73
    Vendor
    Arm
    Product
    Cortex-a73 Firmware
    Vendor
    Arm
    Product
    Cortex-a75
    Vendor
    Arm
    Product
    Cortex-a75 Firmware
    Vendor
    Arm
    Product
    Cortex-a76
    Vendor
    Arm
    Product
    Cortex-a76 Firmware
    Vendor
    Arm
    Product
    Cortex-a76ae
    Vendor
    Arm
    Product
    Cortex-a76ae Firmware
    Vendor
    Arm
    Product
    Cortex-a77
    Vendor
    Arm
    Product
    Cortex-a77 Firmware
    Vendor
    Arm
    Product
    Cortex-a78
    Vendor
    Arm
    Product
    Cortex-a78 Firmware

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High