Insufficient Access Control in Intel E810 Ethernet Controllers
CVE-2020-24497

4.4MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
17 February 2021

Summary

A vulnerability exists in the firmware of Intel E810 Ethernet Controllers prior to version 1.4.1.13 that could allow a privileged user to exploit insufficient access controls. By leveraging local access, an attacker could potentially initiate a denial of service, impacting the availability of the affected network services. This highlights the importance of keeping firmware updated to mitigate risks associated with unauthorized access.

Affected Version(s)

Intel(R) E810 Ethernet Controllers before version 1.4.1.13

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.