CVE-2020-28368
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the gue
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.
MEDIUM · CVSS 4.4
EPSS 0.00067
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0