A lack of pointer-validation logic in the __scone_dispatch component of SCONE before v5.8.0 for Intel SGX allows attackers to access sensitive information.
https://sconedocs.github.io/release5.7/
https://jovanbulck.github.io/files/oakland24-pandora.pdf
https://jovanbulck.github.io/files/ccs19-tale.pdf
Source: Mitre, NVD
Published: 2023-12-30
Updated: 2024-01-08
Base Score: 4.6
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:N
Severity: Medium
Base Score: 5.5
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N