Insufficient Control Flow Management in Intel Ethernet Controller Drivers for VMWare
CVE-2022-21793

5.5MEDIUM

Summary

The vulnerability arises from insufficient control flow management in the Intel Ethernet Controller drivers affecting VMWare. It may allow an authenticated user to potentially execute a denial of service by exploiting this flaw, putting network operations at risk. Users are advised to upgrade to the latest driver versions to mitigate this issue.

Affected Version(s)

Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 2.1.5.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.