Уровень 0 · материалов: 3
В кластер входят документы об уязвимостях и моделях безопасности аппаратных компонентов Intel, но не входят материалы о безопасности программного обеспечения сторонних производителей.
Общие признаки: технологии Intel, безопасность прошивок и оборудования, компрометация доверенной среды (Root of Trust)
Группа выше: Уязвимости процессоров и материнских плат
Смысл: The main idea is that a permanent hardware vulnerability in the Intel CSME boot ROM undermines the entire 'Root of Trust' for Intel platforms, potentially allowing for the compromise of encrypted keys and system authentication that cannot be fully fixed through software patches.
Positive Technologies discovered a non-patchable boot ROM vulnerability in Intel CSME that threatens the hardware root of trust across most Intel chipsets.
Смысл: The main idea is that the Foreshadow vulnerability exposes a critical flaw in Intel's SGX security enclaves, potentially compromising sensitive user data and cloud infrastructure via speculative execution.
Foreshadow is a severe Intel CPU vulnerability that bypasses SGX memory protections, threatening everything from password managers to cloud virtual machines.
Смысл: The main idea is to demonstrate a robust firmware security model using Intel ME as an example, highlighting that hardware-rooted trust, digital signatures, and privilege separation are necessary to protect highly privileged system components from compromise.
An in-depth look at the Intel Management Engine architecture and its rigorous firmware verification process as a model for secure embedded system design.