5.5
CVSSv3

CVE-2023-38021

Published: 30/12/2023 Updated: 17/01/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An issue exists in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform prior to 3.32 for Intel SGX. Lack of pointer-alignment validation logic in entry functions allows a local malicious user to access unauthorized information. This relates to the enclave_ecall function and system call layer.

Vulnerable Product Search on Vulmon Subscribe to Product

fortanix confidential computing manager