7.8
CVE-2022-46487
- EPSS 0.6%
- Veröffentlicht 30.12.2023 03:15:08
- Zuletzt bearbeitet 17.04.2025 20:15:25
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Improper initialization of x87 and SSE floating-point configuration registers in the __scone_entry component of SCONE before 5.8.0 for Intel SGX allows a local attacker to compromise the execution integrity of floating-point operations in an enclave or access sensitive information via side-channel analysis.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.6% | 0.438 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-665 Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
https://jovanbulck.github.io/files/oakland24-pandora.pdf
https://sconedocs.github.io/release5.7/
https://jovanbulck.github.io/files/acsac20-fpu.pdf
https://nvd.nist.gov/vuln/detail/CVE-2020-0561#vulnCurrentDescriptionTitle
https://nvd.nist.gov/vuln/detail/CVE-2020-15107
https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/best-practices/data-operand-independent-timing-isa-guidance.html#inpage-nav-3-3