Out-of-Bounds Write in Intel Ethernet Network Controllers and Adapters
CVE-2022-36382
6MEDIUM
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 16 February 2023
Summary
The vulnerability allows a privileged user to perform an out-of-bounds write in the firmware of specific Intel Ethernet Network Controllers and Adapters. If exploited, this may permit local access that potentially leads to denial of service, impacting network reliability and performance. The affected products include the E810 Series and 700 Series controllers and adapters, emphasizing the need for immediate firmware updates to mitigate risks.
Affected Version(s)
Intel(R) Ethernet Network Controllers and Adapters E810 Series and some Intel(R) Ethernet 700 Series Controllers and Adapters before version 1.7.0.8 and before version 9.101
References
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved