Openenclave is a niche trusted-execution-environment framework that provides tools and libraries for building enclave applications across Intel SGX and other confidential-computing platforms. Its disclosed vulnerabilities center on access-control and initialization issues, reflecting the sensitivity of protecting secrets and state within isolated execution contexts. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openenclave over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37479HIGH Open Enclave is a hardware-agnostic open source library for developing applications that utilize Hardware-based Trusted Execution Environments, also known as Enclaves. There are tw | Jul 17, 2023 | 7.5 | 21 | NO | NO |
CVE-2020-15224MEDIUM In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using the syscalls provided by the sockets.edl is loaded by a mali | Oct 14, 2020 | 6.8 | 18 | NO | NO |
CVE-2020-15107MEDIUM In openenclave before 0.10.0, enclaves that use x87 FPU operations are vulnerable to tampering by a malicious host application. By violating the Linux System V Application Binary I | Jul 15, 2020 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openenclave.
Media articles that mention a CVE ID that affects a product developed by Openenclave — matched by CVE ID, not by vendor name.