Notification

Icon
Error

Plundervolt - Report missing software component

Posted: Thursday, December 12, 2019 5:10:14 PM(UTC)
rader

NWSF

Member Original PosterPosts: 2
1
Like
Hi Guys,

Thank you for providing information on the Intel Plundervolt Vulnerability Report. I ran the scan on our systems and found some vulnerable processors as I expect most organizations will also have.

Reading more information on the site you link to at plundervolt.com, I see that they also say that if you do not use SGX, you do not need to do anything. It looks like the scanning script just checks for the processors listed in the report. Is there a way to also check the vulnerable processors if SGX is enabled or BIOS undervolting is disabled?

If I'm asking the wrong questions it's probably because I'm still wrapping my head around how SGX and the BIOS are related.

Thanks.
Esben.D
#1Esben.D Member Administration Posts: 1,976  
posted: 12/16/2019 10:07:36 AM(UTC)
I took a look at the database documentation, but I didn't see any field that could be used to identify whether SGX is used.

From what I can tell, you can enable SGX in the bios but it can also be software controlled (if you allow that in the bios). You can find more info here: https://software.intel.c...ons-in-your-applications

If you have the SGX software installed on SGX enabled systems, you could just report on the software. Alternatively, you could do a file scan for sgx_uae_service.dll or sgx_urts.dll as the above page mentions.

I don't know if there is a registry key that could be used to detect this.

Active Discussions

Lansweeper Asset Out of Warranty & Asset Out of Warranty in 60 Days Reports
by  RC62N   Go to last post Go to first unread
Last post: Yesterday at 10:29:35 PM(UTC)
Lansweeper Voip Phone to Computer
by  lansend  
Go to last post Go to first unread
Last post: Yesterday at 1:27:10 AM(UTC)
Lansweeper Report Showing custom registry keys scanned
by  impagian   Go to last post Go to first unread
Last post: 1/23/2020 4:01:34 PM(UTC)
Lansweeper Dell Update v3.0
by  gmw158  
Go to last post Go to first unread
Last post: 1/22/2020 5:42:19 PM(UTC)
Lansweeper Report to compare softwareVersion
by  RC62N   Go to last post Go to first unread
Last post: 1/22/2020 4:57:16 PM(UTC)
Lansweeper Dublicate entries (multiple lines with assetname)
by  wkorrubel  
Go to last post Go to first unread
Last post: 1/22/2020 10:10:28 AM(UTC)
Lansweeper Only show string right of character N
by  RC62N   Go to last post Go to first unread
Last post: 1/20/2020 10:36:12 PM(UTC)
Lansweeper Report From Lansweeper For My Company
by  RC62N  
Go to last post Go to first unread
Last post: 1/17/2020 6:59:47 PM(UTC)