Asylo
Vendor:
First CVE: Aug 12, 2020 · Active for 5 years
16
Total CVEs
More Total CVEs than 92% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Asylo over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2020
5 years ago
Most Recent CVE
Aug 2, 2021
1,816 days ago
CVE Severity & Scoring
Asylo16 CVEs
13%
56%
25%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (87.5%)
Network2 (12.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low16 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8904CRITICAL An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the ecall_restore function fails to validate the range of the outpu | Aug 12, 2020 | 9.6 | 28 | NO | NO |
CVE-2021-22550HIGH An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave. It is recommended to update past 0.6.3 or git commit https: | Jun 8, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-22549HIGH An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory. It is recommended to update past 0.6.2 or git commit https://github.com/google/ | Jun 8, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-8935HIGH An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allow an attacker to make an Ecall_restore function call to reallocate untrusted code and overwrite sectio | Dec 15, 2020 | 7.8 | 23 | NO | NO |
CVE-2020-8905MEDIUM A buffer length validation vulnerability in Asylo versions prior to 0.6.0 allows an attacker to read data they should not have access to. The 'enc_untrusted_recvfrom' function gene | Aug 12, 2020 | 6.5 | 21 | NO | NO |
CVE-2020-8944MEDIUM An arbitrary memory write vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to ecall_restore using the attribute output which fails to check t | Dec 15, 2020 | 5.5 | 20 | NO | NO |
CVE-2020-8943MEDIUM An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_recvfrom whose return size was not validated again | Dec 15, 2020 | 5.5 | 20 | NO | NO |
CVE-2020-8939MEDIUM An out of bounds read on the enc_untrusted_inet_ntop function allows an attack to extend the result size that is used by memcpy() to read memory from within the enclave heap. We re | Dec 15, 2020 | 5.5 | 20 | NO | NO |
CVE-2021-22552MEDIUM An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall number in MessageReader that is then used by sysno() and can byp | Aug 2, 2021 | 5.5 | 19 | NO | NO |
CVE-2021-22548HIGH An attacker can change the pointer to untrusted memory to point to trusted memory region which causes copying trusted memory to trusted memory, if the latter is later copied out, i | Jun 8, 2021 | 7.8 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Asylo
Top CWEs
Versions
No cataloged versions.