BaseIncomplete

CWE-1420Exposure of Sensitive Information during Transient Execution

Category: data-exposure

Description

A processor event or prediction may allow incorrect operations (or correct operations with incorrect data) to execute transiently, potentially exposing data over a covert channel.

Common consequences· 1

  • Confidentiality — Read Memory

Potential mitigations· 5

  • [Architecture and Design]The hardware designer can attempt to prevent transient execution from causing observable discrepancies in specific covert channels.
  • [Requirements]
  • [Requirements]
  • [Requirements]
  • [Build and Compilation]

References

  1. https://cwe.mitre.org/data/definitions/1420.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient Execution
CWE
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution
CWE
Information Exposure through Microarchitectural State after Transient Execution
CWE
Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution
CWE
Exposure of Sensitive System Information Due to Uncleared Debug Information
CWE
Sensitive Information Uncleared Before Debug/Power State Transition
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.