PT-2023-26248 · Fortanix+1 · Fortanix Enclaveos Confidential Computing Manager (Ccm) Platform+1
Published
2023-12-29
·
Updated
2024-01-17
·
CVE-2023-38021
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform versions prior to 3.32 for Intel SGX
Description
An issue was discovered in the Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform, which relates to a lack of pointer-alignment validation logic in entry functions. This allows a local attacker to access unauthorized information, specifically through the
enclave ecall function and system call layer.Recommendations
For versions prior to 3.32, update to version 3.32 or later to resolve the issue. As a temporary workaround, consider restricting access to the
enclave ecall function until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fortanix Enclaveos Confidential Computing Manager (Ccm) Platform
Intel Sgx