LiveActive security incident?Get immediate response
CVE Record

CVE-2021-36219: An issue was discovered in SKALE sgxwallet 1.58.3.

An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign that frees a non-initialized pointer from the stack. An attacker can chain multiple enclave calls to prepare a stack that contains a valid address. This address is then freed, resulting in compromised integrity of the enclave. This was resolved after v1.58.3 and not reproducible in sgxwallet v1.77.0.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2021-36219 affects SKALE sgxwallet 1.58.3, a component using Intel SGX enclave logic. Malformed input to an enclave call can cause unsafe memory freeing inside trusted code, compromising enclave integrity. Public sources say the issue was resolved after v1.58.3 and was not reproducible in v1.77.0.

Executive priority

Prioritize this if SKALE sgxwallet is used in production or key-management workflows. With no CVSS or exploitation evidence, urgency depends on confirmed deployment, but enclave integrity issues can affect trust assumptions around protected signing operations.

Technical view

The issue is in ECALL 14 handling within trustedEcdsaSign. Provided input can reach a branch that frees an uninitialized stack pointer. The CVE description states multiple enclave calls can prepare a stack value that is later freed, compromising enclave integrity. No CVSS score, CWE, or complete affected-version range is provided.

Likely exposure

Exposure appears limited to environments running SKALE sgxwallet 1.58.3. The source bundle does not confirm other affected versions, deployment patterns, or internet exposure. Organizations using SKALE infrastructure or sgxwallet builds should verify exact versions and build provenance.

Exploitation context

The CVE description describes attacker-controlled enclave-call sequencing, but the bundle provides no public exploit code, no observed exploitation claim, and KEV is false. Treat exploitation status as unconfirmed. The main concern is integrity impact inside the enclave rather than broad remote compromise evidence.

Researcher notes

Evidence is narrow: the CVE names sgxwallet 1.58.3, describes unsafe freeing in trustedEcdsaSign via ECALL 14, and says the issue was resolved after v1.58.3. The bundle does not provide a full affected range, CWE, CVSS, or exploitation evidence.

Mitigation direction

  • Move sgxwallet deployments off v1.58.3 to a later vendor-supported release.
  • Review SKALE sgxwallet release notes and the referenced fixing commit.
  • Restrict access to components that can invoke sgxwallet enclave calls.
  • Check vendor guidance before applying assumptions about fixed version boundaries.

Validation and detection

  • Inventory all sgxwallet binaries, containers, and build artifacts.
  • Confirm deployed versions are not sgxwallet v1.58.3.
  • Map each deployment to its source commit or release tag.
  • Review enclave-call access paths for unnecessary exposure.
  • Document any compensating controls around sgxwallet invocation.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-36219 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.