Database/Firmware, BMC & network fabric
Intel SGX SDK: Insufficient input validation in the SGX SDK's generated edge routines, letting a local user
CVSS 7.8CVE-2019-14566Firmware, BMC & network fabriccurated
Impact
Insufficient input validation in the SGX SDK's generated edge routines, letting a local user reach information disclosure, privilege escalation, or denial of service against an enclave built with the affected SDK.
Who can reach it
Local authenticated user calling into a vulnerable enclave.
What to do
Rebuild and re-sign enclaves with a fixed SDK, then re-attest. Vendor-side fix; no operator reboot.
References
Related entries
- Intel SGX SDK: Insufficient initialisation in the SGX SDK means enclaves built with the affected SDK can leakCVE-2019-14565 · Intel SGX SDKHigh
- Intel SGX SDK (< 2.6.100.1): Improper initialisation in the SGX SDK gives an authenticated local user a privilegeCVE-2020-0561 · Intel SGX SDK (< 2.6.100.1)High
- AMD PSP trusted applications shipped in the AMD Graphics Driver: Trusted applications bundled with the AMD graphicsCVE-2020-12929 · AMD PSP trusted applications shipped in the AMD Graphics DriverHigh
- AMD Secure Processor (ASP) drivers: Improper parameter handling in the ASP driver layer lets an already-privilegedCVE-2020-12930 · AMD Secure Processor (ASP) driversHigh
- AMD Secure Processor (ASP) kernel: Improper parameter handling in the ASP's own kernel gives a privileged attackerCVE-2020-12931 · AMD Secure Processor (ASP) kernelHigh
- AMD PSP - System Management Network privileged register zeroing: An attacker can zero any privileged register on theCVE-2020-12961 · AMD PSP - System Management Network privileged register zeroingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.