Vulnerability Database

383,371

Total vulnerabilities in the database

CVE-2018-3615 — intel / core_i3

Observable Discrepancy

Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.

  • Published: Aug 14, 2018
  • Updated: Sep 13, 2026
  • CVE: CVE-2018-3615
  • Severity: High
  • Exploit:
  • CISA KEV:

CVSS v3:

  • Severity: High
  • Score: 7.3
  • AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

CVSS v2:

  • Severity: Medium
  • Score: 5.4
  • AV:L/AC:M/Au:N/C:C/I:P/A:N

CWEs:

Software Affected versions
intel / core_i3 = 6006u
intel / core_i3 = 6098p
intel / core_i3 = 6100
intel / core_i3 = 6100e
intel / core_i3 = 6100h
intel / core_i3 = 6100t
intel / core_i3 = 6100te
intel / core_i3 = 6100u
intel / core_i3 = 6102e
intel / core_i3 = 6157u
intel / core_i3 = 6167u
intel / core_i3 = 6300
intel / core_i3 = 6300t
intel / core_i3 = 6320
intel / core_i5 = 650
intel / core_i5 = 655k
intel / core_i5 = 660
intel / core_i5 = 661
intel / core_i5 = 670
intel / core_i5 = 680
intel / core_i5 = 6200u
intel / core_i5 = 6260u
intel / core_i5 = 6267u
intel / core_i5 = 6287u
intel / core_i5 = 6300hq
intel / core_i5 = 6300u
intel / core_i5 = 6350hq
intel / core_i5 = 6360u
intel / core_i5 = 6400
intel / core_i5 = 6400t
intel / core_i5 = 6402p
intel / core_i5 = 6440eq
intel / core_i5 = 6440hq
intel / core_i5 = 6442eq
intel / core_i5 = 6500
intel / core_i5 = 6500t
intel / core_i5 = 6500te
intel / core_i5 = 6585r
intel / core_i5 = 6600
intel / core_i5 = 6600k
intel / core_i5 = 6600t
intel / core_i5 = 6685r
intel / core_i7 = 610e
intel / core_i7 = 620le
intel / core_i7 = 620lm
intel / core_i7 = 620m
intel / core_i7 = 620ue
intel / core_i7 = 620um
intel / core_i7 = 640lm
intel / core_i7 = 640m
intel / core_i7 = 640um
intel / core_i7 = 660lm
intel / core_i7 = 660ue
intel / core_i7 = 660um
intel / core_i7 = 680um
intel / core_i5 = 750
intel / core_i5 = 750s
intel / core_i5 = 760
intel / core_i7 = 7y75
intel / core_i7 = 720qm
intel / core_i7 = 740qm
intel / core_i7 = 7500u
intel / core_i7 = 7560u
intel / core_i7 = 7567u
intel / core_i7 = 7600u
intel / core_i7 = 7660u
intel / core_i7 = 7700
intel / core_i7 = 7700hq
intel / core_i7 = 7700k
intel / core_i7 = 7700t
intel / core_i7 = 7820eq
intel / core_i7 = 7820hk
intel / core_i7 = 7820hq
intel / core_i7 = 7920hq
intel / core_i3 = 8100
intel / core_i3 = 8350k
intel / core_i5 = 8250u
intel / core_i5 = 8350u
intel / core_i5 = 8400
intel / core_i5 = 8600k
intel / core_i7 = 820qm
intel / core_i7 = 840qm
intel / core_i7 = 860
intel / core_i7 = 860s
intel / core_i7 = 870
intel / core_i7 = 870s
intel / core_i7 = 875k
intel / core_i7 = 880
intel / core_i7 = 8550u
intel / core_i7 = 8650u
intel / core_i7 = 8700
intel / core_i7 = 8700k
intel / xeon_e3 = 1515m_v5
intel / xeon_e3 = 1535m_v5
intel / xeon_e3 = 1545m_v5
intel / xeon_e3 = 1558l_v5
intel / xeon_e3 = 1565l_v5
intel / xeon_e3 = 1575m_v5
intel / xeon_e3 = 1578l_v5
intel / xeon_e3 = 1585_v5
intel / xeon_e3 = 1585l_v5
intel / xeon_e3 = 1505m_v6
intel / xeon_e3 = 1535m_v6

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.