CVE Vulnerabilities

CVE-2022-0005

Cleartext Transmission of Sensitive Information

Published: May 12, 2022 | Modified: May 05, 2025
CVSS 3.x
2.4
LOW
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
4.9 MODERATE
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to potentially enable information disclosure via physical access.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
Celeron_g5205u_firmwareIntel- (including)- (including)
Red Hat Enterprise Linux 9RedHatmicrocode_ctl-4:20220809-1.el9*

Potential Mitigations

References