Insufficient Access Control in Intel Ethernet Controllers
CVE-2020-24494

4.4MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
17 February 2021

Summary

The firmware for Intel 722 Ethernet Controllers prior to version 1.4.3 contains an insufficient access control flaw, which may allow a privileged user to potentially cause a denial of service through local access. This situation arises from improper authorization mechanisms, possibly leaving the system vulnerable to unauthorized manipulations.

Affected Version(s)

Intel(R) 722 Ethernet Controllers before version 1.4.3

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.