GPU VulnDB

Database/Firmware, BMC & network fabric

Intel SGX DCAP (datacenter attestation primitives): An improper conditions check in DCAP lets an unauthenticated

CVE-2020-8766Firmware, BMC & network fabriccurated

Impact

An improper conditions check in DCAP lets an unauthenticated adjacent attacker deny service to the attestation path. In a confidential-compute fleet, killing attestation means new workloads cannot start and existing ones cannot renew - an availability failure that looks like a control-plane outage.

Who can reach it

Unauthenticated attacker with adjacent network access to the attestation service - so anything on the same network segment as your PCCS/quote-generation service.

What to do

Upgrade SGX DCAP to 1.6 or later and keep the caching service off flat networks. Userspace service update and restart; no node reboot or firmware.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.