Описание
In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
Ссылки
- ProductThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- ProductThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:apache:teaclave_sgx_sdk:1.1.3:*:*:*:*:rust:*:*
EPSS
Процентиль: 66%
0.00518
Низкий
4.9 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-203
Связанные уязвимости
CVSS3: 4.9
github
больше 3 лет назад
In Rust SGX 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
EPSS
Процентиль: 66%
0.00518
Низкий
4.9 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-203