Database/Firmware, BMC & network fabric
Intel Xeon memory controller configuration (with SGX): Incorrect default permissions on Xeon memory controller
CVSS 7.2CVE-2024-21820Firmware, BMC & network fabriccurated
Impact
Incorrect default permissions on Xeon memory controller configuration when SGX is in use, reachable by a privileged local user for escalation. Same advisory family as the conditions check issue and fixed by the same platform update.
Who can reach it
Privileged local access on the host.
What to do
OEM platform BIOS update, drain and reboot, then re-attest enclaves.
References
Related entries
- Intel Xeon memory controller configuration (with SGX): An improper conditions check in Xeon memory controllerCVE-2024-23918 · Intel Xeon memory controller configuration (with SGX)High
- Intel Xeon memory controller configuration (with SGX): Memory controller configuration registers are left withCVE-2022-33196 · Intel Xeon memory controller configuration (with SGX)High
- Intel Server D50DNP UEFI firmware (PlatformVariableInitDxe): Improper input validation in a UEFI DXE driver on IntelCVE-2024-22095 · Intel Server D50DNP UEFI firmware (PlatformVariableInitDxe)High
- Dell PowerEdge Server BIOS (heap-based buffer overflow): A high-privileged local attacker writes to memory it shouldCVE-2024-22453 · Dell PowerEdge Server BIOS (heap-based buffer overflow)High
- Lenovo XClarity Controller (XCC) - IPMI command handler: A specially crafted IPMI command gives an authenticated XCCCVE-2024-38509 · Lenovo XClarity Controller (XCC) - IPMI command handlerHigh
- AMI AptioV UEFI BIOS (SMM): A memory-bounds bug in the BIOS that lets an attacker execute code outside the intendedCVE-2024-42442 · AMI AptioV UEFI BIOS (SMM)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.