Security information of vulnerability by Speculative Execution and
Indirect Branch Prediction Side Channel Analysis Method
Updated: Dec 5, 2018
Microsoft and Intel published the security information of vulnerability by Speculative Execution and Indirect Branch Prediction Side Channel Analysis Method.
Note : Please be advised that the information will be changed or added without notice.
Vulnerability summary
Regarding details, please refer below Microsoft and Intel site.
- Intel site
- Microsoft site
According to above site, there are below three vulnerabilities.
- CVE-2017-5753 - Bounds check bypass
- CVE-2017-5715 - Branch target injection
- CVE-2017-5754 - Rogue data cache load
New vulnerability was reported by Intel.
- Panasonic Security information
Content of countermeasure
We announce the affected model by these vulnerabilities and the release plan of firmware to mitigate CVE-2017-5715.
Please check the following, Affected Models.
In light of new developments from Intel, Panasonic actively working with Intel to update the new schedule, please check back regularly for updated release dates.
In addition to the firmware update, Panasonic suggests that our customers follow the advice of both the operating system vendor, software vendor and of the chipset vendor to ensure all available protections are being utilised.
Firmware
Target model | OS | Countermeasure module |
---|---|---|
CF-19 | CF-19Z****** (mk8) | Released on November 20, 2018 |
CF-19[5/6/8/9]****** (mk7) | ||
CF-19[0/1/2/3/4]****** (mk6) | ||
CF-19[7/A/B/X/Y]****** (mk5) | To Be Announced | |
CF-19[R/S/T/V/W]****** (mk4) | ||
CF-20 | CF-20[A/B/C/D]****** (mk1) | Released on February 15, 2018 |
CF-31 | CF-31[1/2/3/4]****** (mk5) | Released on March 22, 2018 |
CF-31[W/X/Y]****** (mk4) | Released on November 20, 2018 | |
CF-31[S/U/V]****** (mk3) | ||
CF-31[J/K/M/P/R/T]******* (mk2) 2) | To Be Announced | |
CF-31[A/B/D/F]****** (mk1) | ||
CF-33 | CF-33[A/B/C/L/M/N/V/W]****** (mk1) |
Released on March 9, 2018 Updated on July 10, 2018 |
CF-33[D/E/P/Q]****** (mk1) | Released on February 15, 2018 | |
CF-52 | CF-52V****** (mk5) | Released on November 20, 2018 |
CF-52[S/T]****** (mk4) | To Be Announced | |
CF-52[M/N/P/Q/R]****** (mk3) | ||
CF-53 | CF-53[2/3/4/5/7]****** (mk4) |
Released on April 25, 2018 Updated on October 30, 2018 |
CF-53[S/T/U/V/Y/Z/1]****** (mk3) |
Released on November 20, 2018 | |
CF-53[J/K/L/M/N/P]****** (mk2) | ||
CF-53[A/B/C/D]****** (mk1) | To Be Announced | |
CF-54 | CF-54[G/H/J]****** (mk3) |
Released on March 9, 2018 Updated on July 10, 2018 |
CF-54[D/E/F]****** (mk2) | Released on February 15, 2018 | |
CF-54[A/B/C]****** (mk1) | Released on March 22, 2018 | |
CF-AX2 | CF-AX2L****** (mk1) | Released on December 5, 2018 |
CF-AX3 | CF-AX3E****** (mk2) |
Released on April 25, 2018 Updated on October 30, 2018 |
CF-C1 | CF-C1[B/L]****** (mk2) | To Be Announced |
CF-C1[A/K]****** (mk1) | ||
CF-C2 | CF-C2[C/D]****** (mk2/mk2.5) |
Released on April 25, 2018 Updated on October 30, 2018 |
CF-C2A****** (mk1) | Released on December 5, 2018 | |
CF-D1 | CF-D1[N/Q]****** (mk3) | Released on February 15, 2018 |
CF-D1[G/K]****** (mk2) | Released on November 20, 2018 | |
CF-D1[A/D]****** (mk1) | To Be Announced | |
CF-F9 | CF-F9K****** (mk2) | To Be Announced |
CF-H2 | CF-H2[P/Q/S]****** (mk3) | Released on November 20, 2018 |
CF-H2[F/G/H]****** (mk2) | ||
CF-H2[A/B]****** (mk1) | To Be Announced | |
CF-LX3 | CF-LX3J****** (mk3) |
Released on April 25, 2018 Updated on October 30, 2018 |
CF-LX3E****** (mk2) | ||
CF-LX6 | CF-LX6YDAZTM (mk3) |
Released on March 9, 2018 Updated on July 10, 2018 |
CF-MX4 | CF-MX4E****** (mk1) | Released on March 22, 2018 |
CF-S10 | CF-S10C****** (mk2) | To Be Announced |
CF-S9 | CF-S9K****** (mk2) | To Be Announced |
CF-SX2 | CF-SX2J****** (mk1 Asia model) | Released on December 5, 2018 |
CF-SX4 | CF-SX4E****** (mk1) | Released on March 22, 2018 |
CF-SZ6 | CF-SZ6R***** (mk2) |
Released on March 9, 2018 Updated on July 10, 2018 |
CF-XZ6 | CF-XZ6R***** (mk1) |
Released on March 9, 2018 Updated on July 10, 2018 |
FZ-A2 1) | FZ-A2A****** (mk1) | Released on July 17, 2018 |
FZ-B2 1) | FZ-B2D****** (mk2) | Released on July 17, 2018 |
FZ-B2B****** (mk1) | Released on July 17, 2018 | |
FZ-G1 | FZ-G1[P/Q/R]****** (mk4) | Released on February 15, 2018 |
FZ-G1[J/K/L]****** (mk3) | Released on March 22, 2018 | |
FZ-G1F****** (mk2) |
Released on April 25, 2018 Updated on October 30, 2018 |
|
FZ-G1A****** (mk1) | Released on November 20, 2018 | |
FZ-M1 | FZ-M1D******, FZ-M1ECD***R (mk2 Value-model) |
To Be Announced |
FZ-M1F******, FZ-M1ECF***R (mk2) | Released on February 15, 2018 | |
FZ-M1A****** (mk1 Value-model) | To Be Announced | |
FZ-M1C****** (mk1) |
Released on April 25, 2018 Updated on October 30, 2018 |
|
FZ-Q1 | FZ-Q1A****** (mk1 Value-model) | To Be Announced |
FZ-Q1C****** (mk1) |
Released on April 25, 2018 Updated on October 30, 2018 |
|
FZ-Q2 | FZ-Q2[F/G]****** (mk1) | Released on February 27, 2018 |
FZ-R1 | FZ-R1******* (mk1) | To Be Announced |
FZ-Y1 | FZ-Y1[C/D]****** (mk2) | Released on March 22, 2018 |
UT-MA6000 | UT-MA6****** (mk1) | Released on November 20, 2018 |
UT-MB5000 | UT-MB5****** (mk1) | Released on November 20, 2018 |
- Note 1): Android model.
- Note 2): Except for the following model number.
CF-31JEG57M, CF-31JEG571M, CF-31K1*****, CF-31K5*****
* If there is any error while updating this patch, please contact your regional field support engineer for further assistance.