Database/Firmware, BMC & network fabric
Crypto API Toolkit for Intel SGX: Improper access control in the SGX Crypto API Toolkit lets an authenticated user
CVE-2022-21163Firmware, BMC & network fabriccurated
Impact
Improper access control in the SGX Crypto API Toolkit lets an authenticated user escalate privilege. The toolkit is what many deployments use to put HSM-style key operations inside an enclave, so a break here reaches the keys the enclave was protecting.
Who can reach it
Authenticated user of a system running the Crypto API Toolkit.
What to do
Upgrade to Crypto API Toolkit 2.0 (commit 91ee496) or later and rotate any keys the toolkit held. Userspace/enclave update - requires re-signing and re-attesting the enclave; no reboot.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.