CVE-2023-38022: Fortanix Confidential Computing Manager
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.29 for Intel SGX. Insufficient pointer validation allows a local attacker to access unauthorized information. This relates to strlen and sgx_is_within_user.
Affected products
- Fortanix Confidential Computing Manager: before 3.29 (fixed in 3.29)
Published 2023-12-30. Last modified 2026-06-17.