CWE-1420: Exposure of Sensitive Information during Transient Execution
A processor event or prediction may allow incorrect operations (or correct operations with incorrect data) to execute transiently, potentially exposing data over a covert channel.
4 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-27572 — Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor may allow an informa
- CVE-2024-36349 — A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a re
- CVE-2024-36348 — A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers specu
- CVE-2025-54505 — A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floa
Recently published
- CVE-2025-54505 — A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floa
- CVE-2025-27572 — Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor may allow an informa
- CVE-2024-36348 — A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers specu
- CVE-2024-36349 — A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a re
More specific weaknesses
- CWE-1421 — Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution
- CWE-1422 — Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient Execution
- CWE-1423 — Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution