Insufficient Control Flow Management in Intel Ethernet Controller Drivers for VMWare
CVE-2022-21793
5.5MEDIUM
Summary
The vulnerability arises from insufficient control flow management in the Intel Ethernet Controller drivers affecting VMWare. It may allow an authenticated user to potentially execute a denial of service by exploiting this flaw, putting network operations at risk. Users are advised to upgrade to the latest driver versions to mitigate this issue.
Affected Version(s)
Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 2.1.5.0
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved