Lucene search

K
cve[email protected]CVE-2022-21163
HistoryFeb 16, 2023 - 9:15 p.m.

CVE-2022-21163

2023-02-1621:15:11
web.nvd.nist.gov
19
cve-2022-21163
security
access control
intel
sgx
crypto api
privilege escalation

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

0.0004 Low

EPSS

Percentile

9.1%

Improper access control in the Crypto API Toolkit for Intel® SGX before version 2.0 commit ID 91ee496 may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected configurations

Vulners
NVD
Node
intelcrypto_api_toolkit_for_intel_sgxRange<2.0
OR
intelcrypto_api_toolkit_for_intel_sgxRange<91

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Crypto API Toolkit for Intel(R) SGX",
    "versions": [
      {
        "version": "before version 2.0 commit ID 91ee496",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2022-21163