Vulnerability Database

383,371

Total vulnerabilities in the database

CVE-2018-3619 — intel / core_i7

Exposure of Sensitive Information to an Unauthorized Actor

Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encryption may allow an attacker to recover data via physical access.

  • Published: Jul 10, 2018
  • Updated: Sep 13, 2026
  • CVE: CVE-2018-3619
  • Severity: Low
  • Exploit:
  • CISA KEV:

CVSS v2:

  • Severity: Low
  • Score: 2.1
  • AV:L/AC:L/Au:N/C:P/I:N/A:N

CWEs:

Software Affected versions
intel / core_i7 = 7y75
intel / core_i7 = 7500u
intel / core_i7 = 7560u
intel / core_i7 = 7567u
intel / core_i7 = 7600u
intel / core_i7 = 7660u
intel / core_i7 = 7700
intel / core_i7 = 7700hq
intel / core_i7 = 7700k
intel / core_i7 = 7700t
intel / core_i7 = 7820eq
intel / core_i7 = 7820hk
intel / core_i7 = 7820hq
intel / core_i7 = 7920hq
intel / core_i7 = 8086k
intel / core_i7 = 8500y
intel / core_i7 = 8550u
intel / core_i7 = 8559u
intel / core_i7 = 8565u
intel / core_i7 = 8650u
intel / core_i7 = 8700
intel / core_i7 = 8700b
intel / core_i7 = 8700k
intel / core_i7 = 8700t
intel / core_i7 = 8705g
intel / core_i7 = 8706g
intel / core_i7 = 8709g
intel / core_i7 = 8750h
intel / core_i7 = 8809g
intel / core_i7 = 8850h
intel / core_i5 = 7y54
intel / core_i5 = 7y57
intel / core_i5 = 7200u
intel / core_i5 = 7260u
intel / core_i5 = 7267u
intel / core_i5 = 7287u
intel / core_i5 = 7300hq
intel / core_i5 = 7300u
intel / core_i5 = 7360u
intel / core_i5 = 7400
intel / core_i5 = 7400t
intel / core_i5 = 7440eq
intel / core_i5 = 7440hq
intel / core_i5 = 7442eq
intel / core_i5 = 7500
intel / core_i5 = 7500t
intel / core_i5 = 7600
intel / core_i5 = 7600k
intel / core_i5 = 7600t
intel / core_i5 = 8200y
intel / core_i5 = 8250u
intel / core_i5 = 8259u
intel / core_i5 = 8265u
intel / core_i5 = 8269u
intel / core_i5 = 8300h
intel / core_i5 = 8305g
intel / core_i5 = 8350u
intel / core_i5 = 8400
intel / core_i5 = 8400b
intel / core_i5 = 8400h
intel / core_i5 = 8400t
intel / core_i5 = 8500
intel / core_i5 = 8500b
intel / core_i5 = 8500t
intel / core_i5 = 8600
intel / core_i5 = 8600k
intel / core_i5 = 8600t
intel / core_i3 = 7020u
intel / core_i3 = 7100
intel / core_i3 = 7100e
intel / core_i3 = 7100h
intel / core_i3 = 7100t
intel / core_i3 = 7100u
intel / core_i3 = 7101e
intel / core_i3 = 7101te
intel / core_i3 = 7102e
intel / core_i3 = 7130u
intel / core_i3 = 7167u
intel / core_i3 = 7300
intel / core_i3 = 7300t
intel / core_i3 = 7320
intel / core_i3 = 7350k
intel / core_i3 = 8100
intel / core_i3 = 8100h
intel / core_i3 = 8100t
intel / core_i3 = 8109u
intel / core_i3 = 8130u
intel / core_i3 = 8145u
intel / core_i3 = 8300
intel / core_i3 = 8300t
intel / core_i3 = 8350k
intel / core_i9 = 8950hk
intel / core_m3 = 8100y
intel / core_i5 = 7640x
intel / core_i7 = 3820
intel / core_i7 = 3920xm
intel / core_i7 = 3930k
intel / core_i7 = 3940xm
intel / core_i7 = 3960x
intel / core_i7 = 3970x
intel / core_i7 = 4820k
intel / core_i7 = 4930k
intel / core_i7 = 4930mx
intel / core_i7 = 4940mx
intel / core_i7 = 4960x
intel / core_i7 = 5820k
intel / core_i7 = 5930k
intel / core_i7 = 5960x
intel / core_i7 = 6800k
intel / core_i7 = 6850k
intel / core_i7 = 6900k
intel / core_i7 = 6950x
intel / core_i7 = 7740x
intel / core_i7 = 7800x
intel / core_i7 = 7820x
intel / core_i9 = 7900x
intel / core_i9 = 7920x
intel / core_i9 = 7940x
intel / core_i9 = 7960x
intel / core_i9 = 7980xe

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.