Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ofir Weisse

#38120of 53,635
7.3Total CVSS
Vulnerabilities · 1
PT-2018-1444
7.3
2018-01-03
Intel · Intel Sgx · CVE-2018-3615
**Name of the Vulnerable Software and Affected Versions** Intel SGX (affected versions not specified) Huawei VRP (affected versions not specified) **Description** The issue is related to the implementation of Intel Software Guard Extensions (SGX) technology and speculative execution in microprocessors. It may allow unauthorized disclosure of information from an enclave to an attacker with local user access via a side-channel analysis. This can enable an attacker to read data from the L1 cache, which may contain fragments of data from the protected area after speculative execution. **Recommendations** For Intel SGX, consider disabling speculative execution as a temporary workaround until a patch is available. For Huawei VRP, at the moment, there is no information about a newer version that contains a fix for this vulnerability.