Slyguy

Level 42
Verified
This update will come out as a push if push updating is on, otherwise your next IPS upgrade will contain signatures to block both Spectre and Meltdown.

CPU.Speculative.Execution.Timing.Information.Disclosure | IPS
CPU.Speculative.Execution.Timing.Information.Disclosure
This indicates an attack attempt to exploit an Information Disclosure vulnerability in various systems.
The vulnerability is due to how CPUs can be tricked to leak information from the kernel and other user-mode process memory. A remote attacker can exploit this to gain access to sensitive information. This signature covers for both Spectre and Meltdown vulnerability.

All systems that have CPUs with speculative execution and multiple levels of instruction/data cache.

In addition, Fortigate Appliances are not impacted by Meltdown and/or Spectre. Fortinet products are designed to not permit arbitrary code execution in the user space.
 
Last edited:

Slyguy

Level 42
Verified
My note;

Enter the device CLI and type: execute update-now
and meltdown/spectre IPS signature will be added immediately.
(for those with Fortinet appliances)