CVE-2018-3626

Severity
4.7MEDIUM
EPSS
0.1%
top 67.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMay 14

Description

Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to access unauthorized information.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages2 packages

NVDintel/sgx_sdk< 1.9.6+1
CVEListV5intel_corporation/sgx_sdkbefore version 2.1.2 (Linux) and 1.9.6 (Windows)

🔴Vulnerability Details

2
GHSA
GHSA-r3g2-wgg9-9346: Edger8r tool in the Intel SGX SDK before version 22022-05-14
CVEList
CVE-2018-3626: Edger8r tool in the Intel SGX SDK before version 22018-03-20