Database/Firmware, BMC & network fabric
Intel SGX / DDR4 memory bus (physical interposer): WireTap: a low-cost passive DDR4 interposer reads the memory bus of
Impact
WireTap: a low-cost passive DDR4 interposer reads the memory bus of an SGX machine and recovers the platform's attestation key, letting the attacker forge quotes that Intel's own attestation service accepts. The consequence for an operator is that SGX remote attestation no longer proves anything about a machine an adversary has had physical access to - which includes colocation, transit, and any hardware that has left your custody. Notably the published work reports the attack against production DCAP attestation, not a lab-only configuration.
Who can reach it
Physical access to the machine long enough to install an interposer between the CPU and a DIMM. Not remote, but well within reach of anyone in the supply chain, a colo neighbour with cage access, or an insider in a datacenter you do not own.
What to do
Unpatchable in the field on affected parts - deterministic memory encryption without integrity or freshness is a design property of SGX on these generations, not a bug with a patch. Operator response is procedural: treat physical custody as part of the SGX trust boundary, refuse to accept attestation from hardware outside your custody chain, and plan migration to platforms with stronger memory integrity. Watch for Intel TCB recovery advisories, but do not assume one will close this.
References
Related entries
- Intel SGX / DDR4 memory bus (physical interposer): WireTap: a low-cost passive DDR4 interposer reads the memory bus ofNCVD-2025-001-intel-sgx-ddr4-memory-bus-physic · Intel SGX / DDR4 memory bus (physical interposer)Unscored
- Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing): Battering RAM: a cheap DRAM interposer that aliasesNCVD-2025-013-intel-sgx-and-amd-sev-snp-dram-i · Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing)Unscored
- AMD SEV firmware - arbitrary code execution on the AMD Security Processor (physical): An academic disclosure achievingNCVD-2026-002-amd-sev-firmware-arbitrary-code · AMD SEV firmware - arbitrary code execution on the AMD Security Processor (physical)Unscored
- UEFI Secure Boot (Microsoft 2011 CA/KEK expiry): Not an exploitable flaw but a fleet-wide trust-anchor deadlineNCVD-2026-006-uefi-secure-boot-microsoft-2011 · UEFI Secure Boot (Microsoft 2011 CA/KEK expiry)Unscored
- Community / open-source SONiC (sonic-net): Community SONiC — the open-source NOS that a growing share of cost-optimisedNCVD-2026-013-community-open-source-sonic-soni · Community / open-source SONiC (sonic-net)Unscored
- Rack PDU and UPS management estates as a class (all vendors): PHYSICAL, and the most common real-world findingNCVD-2026-018-rack-pdu-and-ups-management-esta · Rack PDU and UPS management estates as a class (all vendors)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.