Database/Firmware, BMC & network fabric
Intel Xeon processors (SGX/TDX error injection): Unauthorised error injection against SGX or TDX on affected Xeon parts
CVSS 7.2CVE-2022-41804Firmware, BMC & network fabriccurated
Impact
Unauthorised error injection against SGX or TDX on affected Xeon parts gives a privileged user an escalation. Fault injection against a TEE is the same family as Plundervolt: the host corrupts the protected computation until it gives up its secrets.
Who can reach it
Privileged local access on the host.
What to do
Microcode update - late-loadable at boot on most distributions, so this one does not wait on an OEM BIOS release - plus a TCB recovery and re-attestation. Reboot required.
References
Related entries
- NVIDIA DGX BMC (AMI-derived management controller): The BMC's SPX REST API lets an authorised attacker read and writeCVE-2022-42278 · NVIDIA DGX BMC (AMI-derived management controller)High
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's SPX REST API accepts injected shell commandsCVE-2023-25507 · NVIDIA DGX BMC (AMI-derived management controller)High
- AMD Power Management Firmware (PMFW) - unintended proxy to the System Management Unit: The GPU power managementCVE-2023-31313 · AMD Power Management Firmware (PMFW) - unintended proxy to the System Management UnitHigh
- Dataprobe iBoot PDU: Authenticated OS command injection on the PDUCVE-2023-3260 · Dataprobe iBoot PDUHigh
- Intel 4th Gen Xeon on-chip debug and test interface (with SGX or TDX): The on-chip debug and test interface hasCVE-2023-32666 · Intel 4th Gen Xeon on-chip debug and test interface (with SGX or TDX)High
- AMI MegaRAC SPx (SPX REST API): Arbitrary read and write into the memory of the BMC's IPMI server process via the SPXCVE-2023-34341 · AMI MegaRAC SPx (SPX REST API)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.