Database/Firmware, BMC & network fabric
Intel SGX protected memory subsystem: Insufficient access control in the SGX protected-memory subsystem allows
CVSS 4.4CVE-2019-0117Firmware, BMC & network fabriccurated
Impact
Insufficient access control in the SGX protected-memory subsystem allows information disclosure from enclave memory to a privileged local user. Part of the long tail of SGX hardware issues that each force a TCB recovery.
Who can reach it
Privileged local access on the host.
What to do
Microcode/platform firmware update and re-attestation of all enclaves. Where the fix ships in microcode it can be late-loaded at boot; where it ships in the platform BIOS, expect an OEM release and a per-node drain and reboot.
References
Related entries
- Intel E810 Ethernet controller firmware (NVM < 1.4.1.13): Early-generation E810 firmware flaw (an access-controlCVE-2020-24497 · Intel E810 Ethernet controller firmware (NVM < 1.4.1.13)Medium
- Intel E810 Ethernet controller firmware: privileged-local buffer overflows allow denial of serviceCVE-2020-24498 · Intel E810 Ethernet controller firmware (NVM < 1.4.1.13)Medium
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedCVE-2021-0197 · Intel E810 Ethernet controller firmware (NVM)Medium
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedCVE-2021-0198 · Intel E810 Ethernet controller firmware (NVM)Medium
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedCVE-2021-0199 · Intel E810 Ethernet controller firmware (NVM)Medium
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedCVE-2021-33128 · Intel E810 Ethernet controller firmware (NVM)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.