Vulnerability Details CVE-2018-3626
Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to access unauthorized information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.5%
CVSS Severity
CVSS v3 Score 4.7
CVSS v2 Score 1.9
Products affected by CVE-2018-3626
-
cpe:2.3:a:intel:sgx_sdk:-
-
cpe:2.3:a:intel:sgx_sdk:1.6.101.33070
-
cpe:2.3:a:intel:sgx_sdk:1.7.100.35600
-
cpe:2.3:a:intel:sgx_sdk:1.8.105.40539
-
cpe:2.3:a:intel:sgx_sdk:1.9.105.42474
-
cpe:2.3:a:intel:sgx_sdk:1.9.106.43403
-
cpe:2.3:a:intel:sgx_sdk:1.9.6
-
cpe:2.3:a:intel:sgx_sdk:2.0.1
-
cpe:2.3:a:intel:sgx_sdk:2.1
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-