CVE-2023-43490Incorrect Calculation in Intel-microcode

Severity
5.3MEDIUMNVD
OSV6.1
EPSS
0.0%
top 94.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 14
Latest updateMay 29

Description

Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:NExploitability: 0.8 | Impact: 4.0

Affected Packages1 packages

debiandebian/intel-microcode< intel-microcode 3.20240312.1~deb12u1 (bookworm)

🔴Vulnerability Details

3
OSV
intel-microcode vulnerabilities2024-05-29
OSV
CVE-2023-43490: Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a privileged user to potentiall2024-03-14
GHSA
GHSA-vww6-323c-pxr2: Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a privileged user to potentiall2024-03-14

📋Vendor Advisories

3
Ubuntu
Intel Microcode vulnerabilities2024-05-29
Red Hat
kernel: Local information disclosure on Intel(R) Xeon(R) D processors with Intel(R) SGX due to incorrect calculation in microcode2024-02-14
Debian
CVE-2023-43490: intel-microcode - Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D ...2023

💬Community

1
Bugzilla
CVE-2023-43490 kernel: Local information disclosure on Intel(R) Xeon(R) D processors with Intel(R) SGX due to incorrect calculation in microcode2024-03-21