Scontain maintains SCONE, a trusted execution environment and containerization product that enables confidential computing workloads, with its vulnerability disclosures clustering around low-level initialization issues and pointer-management weaknesses characteristic of systems-level memory handling. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scontain over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-29971CRITICAL Scontain SCONE 5.8.0 has an interface vulnerability that leads to state corruption via injected signals. | Jan 10, 2025 | 9.8 | 27 | NO | NO |
CVE-2022-46487HIGH Improper initialization of x87 and SSE floating-point configuration registers in the __scone_entry component of SCONE before 5.8.0 for Intel SGX allows a local attacker to compromi | Dec 30, 2023 | 7.8 | 21 | NO | NO |
CVE-2023-38023MEDIUM An issue was discovered in SCONE Confidential Computing Platform before 5.8.0 for Intel SGX. Lack of pointer-alignment logic in __scone_dispatch and other entry functions allows a | Dec 30, 2023 | 5.5 | 20 | NO | NO |
CVE-2022-46486MEDIUM A lack of pointer-validation logic in the __scone_dispatch component of SCONE before v5.8.0 for Intel SGX allows attackers to access sensitive information. | Dec 30, 2023 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scontain.
Media articles that mention a CVE ID that affects a product developed by Scontain — matched by CVE ID, not by vendor name.