Spectre and Meltdown vulnerability in my company network by Intel CPUs

csabbi

Distinguished
Aug 9, 2013
47
0
18,530
Hi all.

I have just received a task from my team-leader, to check the possibility that does the Spectre and Meltdown affect our system, our software's (which are developed by our team) if we are in a local area network, and in the case when we deliver our product to customers where our HW and SW is in local area network too.

Thanks for your kind replies.

BR
 
Solution
This scenario is very unlikely, but it's possible that if someone had access to your LAN they could exploit either vulnerability and then return to collect the data.

It must be noted these are vulnerabilities, as of yet, no one has exploited them to my knowledge. They have only been proven to exist by security professionals who have exposed them via proof of concept. It will still take hackers sometime to create scripts / software to exploit them as the exact details haven't been advertised. One hopes that the fixes will be in place before hackers can exploit them.

csabbi

Distinguished
Aug 9, 2013
47
0
18,530


OK, thanks for the link. The spectre and meltdown can be exploited even if the devices are not in the www area? even if the can't access the internet? Only in local area network. How can then these attacks, send data to someone, who triggered it?

 

csabbi

Distinguished
Aug 9, 2013
47
0
18,530


Yeah, I get it. And only if the hacker which is in my local network, has some NAT connectivity to the outer world, would be able to send my data outside. Am I correct?
 
This scenario is very unlikely, but it's possible that if someone had access to your LAN they could exploit either vulnerability and then return to collect the data.

It must be noted these are vulnerabilities, as of yet, no one has exploited them to my knowledge. They have only been proven to exist by security professionals who have exposed them via proof of concept. It will still take hackers sometime to create scripts / software to exploit them as the exact details haven't been advertised. One hopes that the fixes will be in place before hackers can exploit them.
 
Solution