Skip to main content

Improper Restriction of Software Interfaces to Hardware Features

CVE-2024-48869

Severity Medium
Score 5.6/10

Summary

Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when using Intel(R) Trust Domain Extensions (Intel(R) TDX) or Intel(R) Software Guard Extensions (Intel(R) SGX) may allow a privileged user to potentially enable escalation of privilege via local access.

  • HIGH
  • LOCAL
  • HIGH
  • CHANGED
  • NONE
  • HIGH
  • LOW
  • NONE

CWE-1256 - Improper Restriction of Software Interfaces to Hardware Features

The product provides software-controllable device functionality for capabilities such as power and clock management, but it does not properly limit functionality that can lead to modification of hardware memory or register bits, or the ability to observe physical side channels.

References

Advisory Timeline

  • Published