PT-2021-15667 · Apache · Apache Teaclave Rust Sgx Sdk

Published

2021-07-14

·

Updated

2022-05-13

·

CVE-2021-24117

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache Teaclave Rust SGX SDK version 1.1.3
Description: A side-channel vulnerability in base64 PEM file decoding allows system-level attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
Recommendations: For Apache Teaclave Rust SGX SDK version 1.1.3, consider disabling the base64 PEM file decoding functionality until a patch is available to prevent potential exploitation. Restrict access to sensitive RSA keys to minimize the risk of information disclosure.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24117

Affected Products

Apache Teaclave Rust Sgx Sdk