Sgx Sdk
Vendor:
First CVE: Mar 20, 2018 · Active for 8 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 15% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sgx Sdk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 2018
8 years ago
Most Recent CVE
Feb 16, 2023
1,257 days ago
CVE Severity & Scoring
Sgx Sdk11 CVEs
91%
9%
All CVEs352,727 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local11 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High2 (18.2%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low9 (81.8%)
High2 (18.2%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18098HIGH Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may allow an escalation of privilege via local access. | Jan 10, 2019 | 7.3 | 24 | NO | NO |
CVE-2022-21166MEDIUM Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local | Jun 15, 2022 | 5.5 | 23 | NO | NO |
CVE-2022-21127MEDIUM Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local | Jun 15, 2022 | 5.5 | 23 | NO | NO |
CVE-2022-21125MEDIUM Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | Jun 15, 2022 | 5.5 | 23 | NO | NO |
CVE-2021-0186MEDIUM Improper input validation in the Intel(R) SGX SDK applications compiled for SGX2 enabled processors may allow a privileged user to potentially escalation of privilege via local acc | Nov 17, 2021 | 6.7 | 23 | NO | NO |
CVE-2022-21123MEDIUM Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | Jun 15, 2022 | 5.5 | 22 | NO | NO |
CVE-2022-26841MEDIUM Insufficient control flow management for the Intel(R) SGX SDK software for Linux before version 2.16.100.1 may allow an authenticated user to potentially enable information disclos | Feb 16, 2023 | 5.5 | 19 | NO | NO |
CVE-2022-26509MEDIUM Improper conditions check in the Intel(R) SGX SDK software may allow a privileged user to potentially enable information disclosure via local access. | Feb 16, 2023 | 5.5 | 19 | NO | NO |
CVE-2021-0001MEDIUM Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access. | Jun 9, 2021 | 4.7 | 19 | NO | NO |
CVE-2018-3626MEDIUM Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to acce | Mar 20, 2018 | 4.7 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Sgx Sdk
Top CWEs
Versions
No cataloged versions.