CVE-2022-38090 describes an improper isolation vulnerability in Intel Processors utilizing Intel Software Guard Extensions (SGX). This flaw allows a highly privileged local attacker to potentially disclose sensitive information. With a CVSS score of 4.4 (Medium), the attack requires high privileges and local access, but has a high impact on confidentiality. There is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code, and community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_gold_5315y_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_gold_5317_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_gold_5318n_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_gold_5318s_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_gold_5318y_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.