Security features bypass in Intel products - CVE-2023-22655

 

Security features bypass in Intel products - CVE-2023-22655

Published: March 12, 2024


Vulnerability identifier: #VU87459
CSH Severity: Low
CVSS v4 BT: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-22655
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a protection mechanism failure in some 3rd and 4th Generation Intel Xeon Processors when using Intel SGX or Intel TDX. A local user can execute arbitrary code with elevated privileges.


Affected software

3rd Generation Intel Xeon Scalable Processors
Intel Xeon D Processors
4th Generation Intel Xeon Platinum processors
4th Generation Intel Xeon Gold Processors
4th Generation Intel Xeon Scalable Processors
4th Generation Intel Xeon Silver Processors
4th Generation Intel Xeon Bronze Processors
Intel Xeon CPU Max Series processors (High Bandwidth Memory HBM)
HPE ProLiant XL290n Gen10 Plus Server
HPE ProLiant XL220n Gen10 Plus Server
HPE Apollo 2000 Gen10 Plus System
HPE Edgeline e920d Server Blade
HPE Edgeline e920 Server Blade
HPE Edgeline e920t Server Blade
HPE ProLiant DL110 Gen10 Plus Telco server
HPE Apollo 4200 Gen10 Plus System
HPE ProLiant DL380 Gen10 Plus server
HPE ProLiant DX360 Gen10 Plus server
HPE ProLiant DX380 Gen10 Plus server
HPE ProLiant DL360 Gen10 Plus server
HPE StoreEasy 1860 Storage
HPE StoreEasy 1660 Storage
Dell Data Protection Central
PowerProtect DP Series Appliance (IDPA)
PowerFlex Appliance
HPE Synergy 480 Gen10 Plus Compute Module
APEX Cloud Platform Foundation Software
PowerSwitch Z9664F-ON
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
APEX Cloud Platform for Red Hat OpenShift
ucode-intel

How to mitigate CVE-2023-22655

Install updates from vendor's website.

PowerFlex Appliance - update to IC-46.380.01
HPE Synergy 480 Gen10 Plus Compute Module - update to 2.00_02-22-2024
HPE ProLiant XL290n Gen10 Plus Server - update to 2.00_02-22-2024
HPE ProLiant XL220n Gen10 Plus Server - update to 2.00_02-22-2024
HPE Apollo 2000 Gen10 Plus System - update to 2.00_02-22-2024
HPE Edgeline e920d Server Blade - update to 2.00_02-22-2024
HPE Edgeline e920 Server Blade - update to 2.00_02-22-2024
HPE Edgeline e920t Server Blade - update to 2.00_02-22-2024
HPE ProLiant DL110 Gen10 Plus Telco server - update to 2.00_02-22-2024
HPE Apollo 4200 Gen10 Plus System - update to 2.00_02-22-2024
HPE ProLiant DL380 Gen10 Plus server - update to 2.00_03-06-2024
HPE ProLiant DX360 Gen10 Plus server - update to 2.00_03-06-2024
HPE ProLiant DX380 Gen10 Plus server - update to 2.00_03-06-2024
HPE ProLiant DL360 Gen10 Plus server - update to 2.00_03-06-2024
HPE StoreEasy 1860 Storage - update to 2.00_03-06-2024
HPE StoreEasy 1660 Storage - update to 2.00_03-06-2024
APEX Cloud Platform Foundation Software - update to 03.00.04.01
PowerSwitch Z9664F-ON - update to 3.54.5.1-9
APEX Cloud Platform for Red Hat OpenShift - update to 4.13.39
ucode-intel - update to 20240312-150200.38.1

External References

Related Security Bulletins