PT-2023-26249 · Fortanix · Fortanix Enclaveos Confidential Computing Manager (Ccm) Platform

CVE-2023-38022

·

Publicado

2023-12-29

·

Atualizado

2024-01-17

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform versions prior to 3.29
Description An issue was discovered in the Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform, allowing a local attacker to access unauthorized information due to insufficient pointer validation. This issue relates to strlen and sgx is within user.
Recommendations For versions prior to 3.29, update to version 3.29 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-38022

Produtos afetados

Fortanix Enclaveos Confidential Computing Manager (Ccm) Platform