Lucene search

K
nvd[email protected]NVD:CVE-2023-38023
HistoryDec 30, 2023 - 3:15 a.m.

CVE-2023-38023

2023-12-3003:15:08
web.nvd.nist.gov
2
scone confidential computing platform
intel sgx
vulnerability
aepic leak
local attacker
unauthorized information

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

5.1%

An issue was discovered in SCONE Confidential Computing Platform before 5.8.0 for Intel SGX. Lack of pointer-alignment logic in __scone_dispatch and other entry functions allows a local attacker to access unauthorized information, aka an “AEPIC Leak.”

Affected configurations

Nvd
Node
scontainsconeRange<5.8.0
AND
intelsoftware_guard_extensionsMatch-
VendorProductVersionCPE
scontainscone*cpe:2.3:a:scontain:scone:*:*:*:*:*:*:*:*
intelsoftware_guard_extensions-cpe:2.3:a:intel:software_guard_extensions:-:*:*:*:*:*:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2023-38023