Improper initialization of x87 and SSE floating-point configuration registers in...
Vulnerability Description
Improper initialization of x87 and SSE floating-point configuration registers in the __scone_entry component of SCONE before 5.8.0 for Intel SGX allows a local attacker to compromise the execution integrity of floating-point operations in an enclave or access sensitive information via side-channel analysis.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-46487
Credits & Attribution
No credits recorded in the NVD database.
References
- https://sconedocs.github.io/release5.7/
- https://jovanbulck.github.io/files/acsac20-fpu.pdf
- https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/best-practices/data-operand-independent-timing-isa-guidance.html#inpage-nav-3-3
- https://nvd.nist.gov/vuln/detail/CVE-2020-15107
- https://nvd.nist.gov/vuln/detail/CVE-2020-0561#vulnCurrentDescriptionTitle
- https://jovanbulck.github.io/files/oakland24-pandora.pdf
Affected Vendor
scontain
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.