Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-12904

In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.8%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2019-12904
  • Gnupg » Libgcrypt » Version: 1.8.4
    cpe:2.3:a:gnupg:libgcrypt:1.8.4
  • Opensuse » Leap » Version: 15.0
    cpe:2.3:o:opensuse:leap:15.0


Contact Us

Shodan ® - All rights reserved