Database/Firmware, BMC & network fabric
Intel SGX SDK (< 2.6.100.1): Improper initialisation in the SGX SDK gives an authenticated local user a privilege
CVSS 7.8CVE-2020-0561Firmware, BMC & network fabriccurated
Impact
Improper initialisation in the SGX SDK gives an authenticated local user a privilege escalation path against enclaves built with it.
Who can reach it
Local authenticated user against a vulnerable enclave.
What to do
Rebuild enclaves with SGX SDK 2.6.100.1 or later and re-attest. Vendor-side.
References
Related entries
- AMD PSP trusted applications shipped in the AMD Graphics Driver: Trusted applications bundled with the AMD graphicsCVE-2020-12929 · AMD PSP trusted applications shipped in the AMD Graphics DriverHigh
- AMD Secure Processor (ASP) drivers: Improper parameter handling in the ASP driver layer lets an already-privilegedCVE-2020-12930 · AMD Secure Processor (ASP) driversHigh
- AMD Secure Processor (ASP) kernel: Improper parameter handling in the ASP's own kernel gives a privileged attackerCVE-2020-12931 · AMD Secure Processor (ASP) kernelHigh
- AMD PSP - System Management Network privileged register zeroing: An attacker can zero any privileged register on theCVE-2020-12961 · AMD PSP - System Management Network privileged register zeroingHigh
- ASPEED video engine driver clock/reset sequencing (drivers/media/platform/aspeed): The driver brings the video engineCVE-2020-36787 · ASPEED video engine driver clock/reset sequencing (drivers/media/platform/aspeed)High
- Intel RDMA driver for Ethernet X722 and 800 series (Linux): Improper input validation in the Intel RDMA Linux driverCVE-2021-0084 · Intel RDMA driver for Ethernet X722 and 800 series (Linux)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.