Cyber Resilience

CVE-2023-38023

Scontain Scone ≤ 5.8.0

Published
30 December 2023
Modified
21 November 2024
CVSS Score v3.1 5.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0022 12th percentile
Risk Priority 42 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2023-38023 is a medium-severity an unspecified weakness vulnerability in Scontain Scone. Its CVSS base score is 5.5 (Medium).

Operationally, ranked at the 12th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

An issue was discovered in SCONE Confidential Computing Platform before 5.8.0 for Intel SGX. Lack of pointer-alignment logic in __scone_dispatch and other entry functions allows a local attacker to access unauthorized information, aka an "AEPIC Leak."

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-29971Same product: Scontain Scone
CVE-2023-38566Same vendor: Intel
CVE-2025-20090Same vendor: Intel
CVE-2024-39609Same vendor: Intel
CVE-2023-22342Same vendor: Intel
CVE-2024-36245Same vendor: Intel
CVE-2023-43748Same vendor: Intel
CVE-2024-23495Same vendor: Intel
CVE-2024-34163Same vendor: Intel
CVE-2023-33875Same vendor: Intel

Affected Assets

scontain
scone
≤ 5.8.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References