CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2022-23960: xen Version not applicable in the source CPE; +22 more affected products

CVE-2022-23960. CVSS 3.1 base score 5.6 (MEDIUM, NVD). EPSS 0.00499 (percentile 0.40833), scored 2026-10-08.

Affected technology

xen · Version not applicable in the source CPE
xen

cortex-r7 firmware · Version not applicable in the source CPE
arm

cortex-r8 firmware · Version not applicable in the source CPE
arm

cortex-a57 firmware · Version not applicable in the source CPE
arm

cortex-a65 firmware · Version not applicable in the source CPE
arm

cortex-a65ae firmware · Version not applicable in the source CPE
arm

cortex-a710 firmware · Version not applicable in the source CPE
arm

cortex-a72 firmware · Version not applicable in the source CPE
arm

cortex-a73 firmware · Version not applicable in the source CPE
arm

cortex-a75 firmware · Version not applicable in the source CPE
arm

cortex-a76 firmware · Version not applicable in the source CPE
arm

cortex-a76ae firmware · Version not applicable in the source CPE
arm

cortex-a77 firmware · Version not applicable in the source CPE
arm

cortex-a78 firmware · Version not applicable in the source CPE
arm

cortex-a78ae firmware · Version not applicable in the source CPE
arm

cortex-x1 firmware · Version not applicable in the source CPE
arm

cortex-x2 firmware · Version not applicable in the source CPE
arm

neoverse-e1 firmware · Version not applicable in the source CPE
arm

neoverse-v1 firmware · Version not applicable in the source CPE
arm

neoverse n1 firmware · Version not applicable in the source CPE
arm

neoverse n2 firmware · Version not applicable in the source CPE
arm

debian linux · 9.0
debian

debian linux · 10.0
debian

n/a · n/a
Vendor not specified by the source

Description’s affected range: through 2022-03-08 do not properly restrict cache speculation

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. NVD’s CVSS 3.1 assessment (base score 5.6/10) rates confidentiality impact as high; integrity and availability impact as none.

Published

CCR priority
22.5 /100 (P4)
CVSS 3.1
5.6 /10 · CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N · NVD
EPSS
0.00499 · percentile 0.40833 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2022-23960.html