VYPR

Confidential Computing Manager

by Fortanix

CVEs (2)

  • CVE-2023-38022MedDec 30, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.29 for Intel SGX. Insufficient pointer validation allows a local attacker to access unauthorized information. This relates to strlen and sgx_is_within_user.

  • CVE-2023-38021MedDec 30, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.32 for Intel SGX. Lack of pointer-alignment validation logic in entry functions allows a local attacker to access unauthorized information. This relates to the enclave_ecall…