Skale develops SGXWallet, a cryptographic key management tool designed for secure enclave environments, and has a compact vulnerability footprint centered on memory-safety issues within this specialized component. The observed weakness classes—including access of uninitialized pointers, classic buffer overflows, NULL-pointer dereferences, and out-of-bounds writes—reflect the low-level memory handling inherent to trusted execution context implementations. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Skale over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36219CRITICAL An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign that frees a non-initialized pointer from the stack. An att | Sep 27, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-36218HIGH An issue was discovered in SKALE sgxwallet 1.58.3. sgx_disp_ippsAES_GCMEncrypt allows an out-of-bounds write, resulting in a segfault and compromised enclave. This issue describes | Sep 27, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-36199HIGH An issue in skalenetwork sgxwallet v.1.9.0 and below allows an attacker to cause a denial of service via the trustedGenerateEcdsaKey component. | Aug 25, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-36198HIGH Buffer Overflow vulnerability in skalenetwork sgxwallet v.1.9.0 allows an attacker to cause a denial of service via the trustedBlsSignMessage function. | Aug 25, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Skale.
Media articles that mention a CVE ID that affects a product developed by Skale — matched by CVE ID, not by vendor name.