CVE-2020-8698: Medium severity microcode vulnerability
A flaw was found in the CPU microarchitecture where a local attacker is able to abuse a timing issue which may allow them to infer internal architectural state from previous executions on the CPU.
Other sources
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2020:5084
- RHSA-2020:5189
- RHSA-2020:5184
- RHSA-2020:5083
- RHSA-2021:3028
- RHSA-2020:5188
- RHSA-2021:3323
- RHSA-2020:5183
- RHSA-2021:3322
- RHSA-2020:5182
- RHSA-2021:3255
- RHSA-2021:3317
- RHSA-2020:5181
- RHSA-2020:5190
- RHSA-2021:3029
- RHSA-2020:5085
- RHSA-2021:3027
- RHSA-2020:5186
- RHSA-2020:5369
- RHSA-2021:3176
- RHSA-2020:5185
- RHSA-2021:3364
Frequently Asked Questions
What is CVE-2020-8698?
CVE-2020-8698 is a vulnerability in the CPU microarchitecture that allows a local attacker to infer internal architectural state from previous executions on the CPU.
Which software are affected by CVE-2020-8698?
Intel Microcode, NetApp Clustered Data ONTAP, Netapp Hci Compute Node Bios, Netapp Hci Storage Node Bios, Netapp Solidfire Bios, Fedoraproject Fedora, Debian Debian Linux, Siemens Simatic Field Pg M5 Firmware, Siemens Simatic Field Pg M6 Firmware, Siemens Simatic Ipc427e Firmware, Siemens Simatic Ipc477e Firmware, Siemens Simatic Ipc477e Pro Firmware, Siemens Simatic Ipc627e Firmware, Siemens Simatic Ipc647e Firmware, Siemens Simatic Ipc677e Firmware, Siemens Simatic Ipc847e Firmware, Siemens Simatic Itp1000 Firmware are affected by CVE-2020-8698.
What is the severity of CVE-2020-8698?
CVE-2020-8698 has a severity score of 5.5 (medium).
Is Intel Core I3-1000g1 vulnerable to CVE-2020-8698?
No, Intel Core I3-1000g1 is not vulnerable to CVE-2020-8698.
How can I fix CVE-2020-8698?
To fix CVE-2020-8698, it is recommended to apply the necessary patches and microcode updates provided by the software vendors.