Database/Firmware, BMC & network fabric
Intel CPUs with SGX, attacked over the SVID serial bus between the voltage regulator and the CPU package: Re-runs
Impact
Re-runs the Plundervolt fault injection using a cheap external microcontroller wired to the motherboard's voltage-regulator bus, so it works on hosts that have already applied the Plundervolt microcode fix - that fix only disabled the software MSR, it did not stop voltage manipulation reaching the package. Recovers keys from enclaves and corrupts enclave computation. Intel's position is that physical attacks are outside the SGX threat model, so there is no patch and there will not be one. The operator consequence is concrete: if an attacker can put hands on the chassis, SGX and by extension the confidential-computing guarantee on that machine are void.
Who can reach it
Physical access to the motherboard, roughly 30 dollars of hardware, and a few minutes to attach to the SVID bus. Relevant threat models: colocation facilities where you do not control the cage, hardware in transit, decommissioned or RMA'd nodes, hosting partners, and anyone with datacenter floor access. Not reachable remotely.
What to do
UNPATCHABLE by design - Intel classifies it as out of scope, so there is no microcode, BIOS or kernel fix to deploy. Mitigation is entirely physical and procedural: chassis intrusion detection wired into the BMC and actually alarmed, tamper-evident seals, controlled cage access with audited entry logs, and refusing to run confidential workloads on hardware whose physical custody you cannot vouch for. If you sell confidential compute, this is a contractual and facility-security question, not an engineering one - and it should shape which sites you are willing to place attested workloads in.
References
Related entries
- DDR4 chips from all three major DRAM manufacturers; worsens as process nodes shrink: A different read-disturbanceNCVD-2023-001-ddr4-chips-from-all-three-major · DDR4 chips from all three major DRAM manufacturers; worsens as process nodes shrinkUnscored
- Gigabyte UEFI firmware (OEM update-dropper in firmware): Gigabyte firmware shipped a UEFI module that writes a WindowsNCVD-2023-001-gigabyte-uefi-firmware-oem-updat · Gigabyte UEFI firmware (OEM update-dropper in firmware)Unscored
- Intel processors with Linear Address Masking (LAM): SLAM: Linear Address Masking, a feature intended to let softwareNCVD-2023-001-intel-processors-with-linear-add · Intel processors with Linear Address Masking (LAM)Unscored
- MSI / Intel Boot Guard OEM key leak: The Money Message ransomware dump exposed MSI's firmware image-signing privateNCVD-2023-001-msi-intel-boot-guard-oem-key-lea · MSI / Intel Boot Guard OEM key leakUnscored
- Intel SGX (cache side channel on sub-cacheline access): TeeJam: shows that SGX's cache-based side-channel resistance isNCVD-2024-001-intel-sgx-cache-side-channel-on · Intel SGX (cache side channel on sub-cacheline access)Unscored
- Platform attestation as an operational control (fTPM vs discrete TPM trust): Design-level: on most GPU servers the TPMNCVD-2024-001-platform-attestation-as-an-opera · Platform attestation as an operational control (fTPM vs discrete TPM trust)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.