PT-2018-1444 · Intel+2 · Intel Sgx+2

Baris Kasikci

+9

·

Published

2018-01-03

·

Updated

2020-08-24

·

CVE-2018-3615

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Intel SGX (affected versions not specified) Huawei VRP (affected versions not specified)
Description The issue is related to the implementation of Intel Software Guard Extensions (SGX) technology and speculative execution in microprocessors. It may allow unauthorized disclosure of information from an enclave to an attacker with local user access via a side-channel analysis. This can enable an attacker to read data from the L1 cache, which may contain fragments of data from the protected area after speculative execution.
Recommendations For Intel SGX, consider disabling speculative execution as a temporary workaround until a patch is available. For Huawei VRP, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2253
BDU:2018-00994
CVE-2018-3615
DLA-1506-1
MGASA-2018-0344
MGASA-2018-0345
MGASA-2018-0346
MGASA-2018-0347

Affected Products

Alt Linux
Huawei Vrp
Intel Sgx