CVE-2023-38023: Medium severity scone vulnerability
An issue was discovered in SCONE Confidential Computing Platform before 5.8.0 for Intel SGX. Lack of pointer-alignment logic in sconedispatch and other entry functions allows a local attacker to access unauthorized information, aka an "AEPIC Leak."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38023?
CVE-2023-38023 has been classified as a medium severity vulnerability due to its potential for local attackers to access unauthorized information.
How do I fix CVE-2023-38023?
To mitigate CVE-2023-38023, upgrade your SCONE Confidential Computing Platform to version 5.8.0 or later.
Who is affected by CVE-2023-38023?
CVE-2023-38023 affects the SCONE Confidential Computing Platform versions prior to 5.8.0 when used with Intel SGX.
What type of attack does CVE-2023-38023 enable?
CVE-2023-38023 allows local attackers to exploit a lack of pointer-alignment logic to access sensitive information.
Is CVE-2023-38023 specific to any hardware?
Yes, CVE-2023-38023 specifically affects implementations using Intel Software Guard Extensions in SCONE.