PT-2021-15667 · Apache · Apache Teaclave Rust Sgx Sdk
Published
2021-07-14
·
Updated
2022-05-13
·
CVE-2021-24117
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Teaclave Rust SGX SDK version 1.1.3
Description:
A side-channel vulnerability in base64 PEM file decoding allows system-level attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
Recommendations:
For Apache Teaclave Rust SGX SDK version 1.1.3, consider disabling the base64 PEM file decoding functionality until a patch is available to prevent potential exploitation. Restrict access to sensitive RSA keys to minimize the risk of information disclosure.
Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Teaclave Rust Sgx Sdk