First published: Sat Dec 30 2023(Updated: )
An issue was discovered in SCONE Confidential Computing Platform before 5.8.0 for Intel SGX. Lack of pointer-alignment logic in __scone_dispatch and other entry functions allows a local attacker to access unauthorized information, aka an "AEPIC Leak."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Scontain SCONE | <5.8.0 | |
Intel Software Guard Extensions |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38023 has been classified as a medium severity vulnerability due to its potential for local attackers to access unauthorized information.
To mitigate CVE-2023-38023, upgrade your SCONE Confidential Computing Platform to version 5.8.0 or later.
CVE-2023-38023 affects the SCONE Confidential Computing Platform versions prior to 5.8.0 when used with Intel SGX.
CVE-2023-38023 allows local attackers to exploit a lack of pointer-alignment logic to access sensitive information.
Yes, CVE-2023-38023 specifically affects implementations using Intel Software Guard Extensions in SCONE.