Database/Firmware, BMC & network fabric
Intel SGX DCAP (datacenter attestation primitives): An improper conditions check in DCAP lets an unauthenticated
Impact
An improper conditions check in DCAP lets an unauthenticated adjacent attacker deny service to the attestation path. In a confidential-compute fleet, killing attestation means new workloads cannot start and existing ones cannot renew - an availability failure that looks like a control-plane outage.
Who can reach it
Unauthenticated attacker with adjacent network access to the attestation service - so anything on the same network segment as your PCCS/quote-generation service.
What to do
Upgrade SGX DCAP to 1.6 or later and keep the caching service off flat networks. Userspace service update and restart; no node reboot or firmware.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.