Improper Input Validation in Intel 700 Series Ethernet Driver
CVE-2025-24486

8.8HIGH

Key Information:

Vendor

Intel

Vendor
CVE Published:
12 August 2025

What is CVE-2025-24486?

The vulnerability arises from improper input validation in the Linux kernel-mode driver for Intel's 700 Series Ethernet, allowing authenticated users to escalate privileges through local access. This could lead to unauthorized actions within the system, highlighting the importance of updating to version 2.28.5 or later to mitigate potential risks. For detailed information, refer to the advisory provided by Intel.

Affected Version(s)

Intel(R) 700 Series Ethernet before version 2.28.5

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-24486 : Improper Input Validation in Intel 700 Series Ethernet Driver