Vulnerability Description
Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to access unauthorized information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Sgx Sdk | < 1.9.6 |
| Microsoft | Windows | - |
| Linux | Linux Kernel | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103479Third Party AdvisoryVDB Entry
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00117&languageiVendor Advisory
- http://www.securityfocus.com/bid/103479Third Party AdvisoryVDB Entry
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00117&languageiVendor Advisory
FAQ
What is CVE-2018-3626?
CVE-2018-3626 is a vulnerability with a CVSS score of 4.7 (MEDIUM). Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to access unauthorized info...
How severe is CVE-2018-3626?
CVE-2018-3626 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-3626?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Sgx Sdk, Microsoft Windows, Linux Linux Kernel.