Lucene search

K
cveMitreCVE-2022-46487
HistoryDec 30, 2023 - 3:15 a.m.

CVE-2022-46487

2023-12-3003:15:08
CWE-665
mitre
web.nvd.nist.gov
20
cve-2022-46487
scone
intel sgx
security
vulnerability
side-channel analysis

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

15.7%

Improper initialization of x87 and SSE floating-point configuration registers in the __scone_entry component of SCONE before 5.8.0 for Intel SGX allows a local attacker to compromise the execution integrity of floating-point operations in an enclave or access sensitive information via side-channel analysis.

Affected configurations

Nvd
Node
scontainsconeRange<5.8.0
VendorProductVersionCPE
scontainscone*cpe:2.3:a:scontain:scone:*:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

15.7%

Related for CVE-2022-46487