CVE-2020-28368: Medium severity xen xapi vulnerability
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-28368?
CVE-2020-28368 is classified as a medium severity vulnerability due to its potential to expose sensitive information through side-channel attacks.
How do I fix CVE-2020-28368?
To mitigate CVE-2020-28368, you should update Xen to versions 4.14.6 or later, or to the specified remedy versions available from Debian and Fedora.
Who is affected by CVE-2020-28368?
CVE-2020-28368 affects administrators of guest operating systems running vulnerable versions of Xen.
What type of attack does CVE-2020-28368 involve?
CVE-2020-28368 involves a side-channel attack leveraging power/energy monitoring interfaces to extract sensitive information.
Can CVE-2020-28368 be exploited remotely?
CVE-2020-28368 requires local access to the guest OS, making it less likely to be exploited remotely, but still poses a significant risk.