Database/Firmware, BMC & network fabric
Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure): A protection mechanism in 3rd and 4th generation
CVSS 6.1CVE-2023-22655Firmware, BMC & network fabriccurated
Impact
A protection mechanism in 3rd and 4th generation Xeon fails when SGX or TDX is in use, letting a privileged local user escalate. Affects the exact Xeon generations most AI datacenter hosts were built on between 2021 and 2024.
Who can reach it
Privileged local access on the host.
What to do
Microcode update plus TCB recovery. Late-loadable microcode, reboot, then re-attest enclaves and trust domains.
References
Related entries
- shim (mok.c mirror_one_esl): NULL pointer dereference while printing an error message stops the node from bootingCVE-2023-40546 · shim (mok.c mirror_one_esl)Medium
- Linux kernel (drivers/pci/switch): If a userspace process is holding the Switchtec management character device openCVE-2023-52617 · Linux kernel (drivers/pci/switch)Medium
- Avocent DSR2030 / SVIP1020 KVM-over-IP appliance: A reflected XSS in the appliance's web interface lets an attackerCVE-2024-34923 · Avocent DSR2030 / SVIP1020 KVM-over-IP applianceMedium
- Intel Xeon 6 E-core with TDX or SGX: Improper restriction of software interfaces to hardware features on Xeon 6 E-coreCVE-2024-48869 · Intel Xeon 6 E-core with TDX or SGXMedium
- Intel Ethernet E810 Series and Ethernet 700 Series firmware: Out-of-bounds write in firmware across both the E810 lineCVE-2022-36382 · Intel Ethernet E810 Series and Ethernet 700 Series firmwareMedium
- Intel processors with SGX (shared resource isolation): Improper isolation of shared microarchitectural resources lets aCVE-2022-38090 · Intel processors with SGX (shared resource isolation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.