Database/Firmware, BMC & network fabric
Intel Xeon memory controller configuration (with SGX): An improper conditions check in Xeon memory controller
CVSS 8.8CVE-2024-23918Firmware, BMC & network fabriccurated
Impact
An improper conditions check in Xeon memory controller configuration under SGX gives a privileged local user privilege escalation. Highest-scored of the memory-controller-plus-SGX family and the one to prioritise if you run SGX on Xeon.
Who can reach it
Privileged local access on the host.
What to do
OEM platform BIOS update plus TCB recovery and re-attestation. Drain and reboot per node; OEM availability is the long pole.
References
Related entries
- Intel Xeon memory controller configuration (with SGX): Memory controller configuration registers are left withCVE-2022-33196 · Intel Xeon memory controller configuration (with SGX)High
- Intel Xeon memory controller configuration (with SGX): Incorrect default permissions on Xeon memory controllerCVE-2024-21820 · Intel Xeon memory controller configuration (with SGX)High
- Linux guest kernel - hypervisor-injected int 0x80 on the 32-bit syscall path (SEV-SNP / SEV-ES, AMD-SB-3008): TheCVE-2024-25744 · Linux guest kernel - hypervisor-injected int 0x80 on the 32-bit syscall path (SEV-SNP / SEV-ES, AMD-SB-3008)High
- AMI AptioV BIOS (improper input validation, SMM): A local attacker overwrites arbitrary memory and executes code at SMMCVE-2024-33659 · AMI AptioV BIOS (improper input validation, SMM)High
- Dell SmartFabric OS10 (execution with unnecessary privileges): A low-privileged attacker escalates through an OS10CVE-2024-48013 · Dell SmartFabric OS10 (execution with unnecessary privileges)High
- Dell SmartFabric OS10 (default password): A default password in SmartFabric OS10 across 10.5.4.x through 10.6.0.xCVE-2024-49559 · Dell SmartFabric OS10 (default password)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.