CVE-2022-48251

The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not directly caused by or related to the Arm architecture."
References
Link Resource
https://eprint.iacr.org/2022/230 Technical Description Third Party Advisory
https://eshard.com/posts/sca-attacks-on-armv8 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:arm:cortex-a53_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a53:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:arm:cortex-a55_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a55:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:arm:cortex-a57_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a57:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:arm:cortex-a72_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a72:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:arm:cortex-a73_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a73:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:arm:cortex-a75_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a75:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:arm:cortex-a76_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a76:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:arm:cortex-a76ae_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a76ae:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:arm:cortex-a77_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a77:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:arm:cortex-a78_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a78:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:56

Type Values Removed Values Added
Summary ** DISPUTED ** The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not directly caused by or related to the Arm architecture." The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not directly caused by or related to the Arm architecture."

20 Jan 2023, 07:54

Type Values Removed Values Added
First Time Arm cortex-a78
Arm cortex-a77
Arm cortex-a76
Arm cortex-a78 Firmware
Arm cortex-a76 Firmware
Arm cortex-a53 Firmware
Arm cortex-a77 Firmware
Arm cortex-a75
Arm cortex-a55
Arm cortex-a73 Firmware
Arm cortex-a55 Firmware
Arm cortex-a57
Arm cortex-a76ae
Arm cortex-a72
Arm
Arm cortex-a72 Firmware
Arm cortex-a75 Firmware
Arm cortex-a53
Arm cortex-a73
Arm cortex-a76ae Firmware
Arm cortex-a57 Firmware
CPE cpe:2.3:h:arm:cortex-a57:-:*:*:*:*:*:*:*
cpe:2.3:o:arm:cortex-a77_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a76ae:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a78:-:*:*:*:*:*:*:*
cpe:2.3:o:arm:cortex-a78_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a75:-:*:*:*:*:*:*:*
cpe:2.3:o:arm:cortex-a75_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:arm:cortex-a55_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:arm:cortex-a73_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:arm:cortex-a76ae_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:arm:cortex-a53_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a72:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a77:-:*:*:*:*:*:*:*
cpe:2.3:o:arm:cortex-a57_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a55:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a76:-:*:*:*:*:*:*:*
cpe:2.3:o:arm:cortex-a72_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a53:-:*:*:*:*:*:*:*
cpe:2.3:o:arm:cortex-a76_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arm:cortex-a73:-:*:*:*:*:*:*:*
References (MISC) https://eprint.iacr.org/2022/230 - (MISC) https://eprint.iacr.org/2022/230 - Technical Description, Third Party Advisory
References (MISC) https://eshard.com/posts/sca-attacks-on-armv8 - (MISC) https://eshard.com/posts/sca-attacks-on-armv8 - Exploit, Third Party Advisory
CWE CWE-203
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

10 Jan 2023, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-10 07:15

Updated : 2024-04-11 01:17


NVD link : CVE-2022-48251

Mitre link : CVE-2022-48251

CVE.ORG link : CVE-2022-48251


JSON object : View

Products Affected

arm

  • cortex-a77_firmware
  • cortex-a78_firmware
  • cortex-a73
  • cortex-a72
  • cortex-a53_firmware
  • cortex-a75_firmware
  • cortex-a57_firmware
  • cortex-a55
  • cortex-a76ae
  • cortex-a78
  • cortex-a72_firmware
  • cortex-a75
  • cortex-a55_firmware
  • cortex-a76_firmware
  • cortex-a76
  • cortex-a73_firmware
  • cortex-a57
  • cortex-a77
  • cortex-a53
  • cortex-a76ae_firmware
CWE
CWE-203

Observable Discrepancy