First published: Thu Nov 14 2019(Updated: )
Buffer overflow in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an unauthenticated user to potentially enable an escalation of privilege via an adjacent access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Ethernet Controller x710-tm4 | <7.0 | |
Intel Ethernet Controller x710-tm4 | ||
Intel Ethernet Controller x710-at2 | <7.0 | |
Intel Ethernet Controller x710-at2 | ||
Intel Ethernet Controller XXV710-AM2 | <7.0 | |
Intel Ethernet Controller xxv710-am2 firmware | ||
Intel Ethernet Controller XXV710-AM1 | <7.0 | |
Intel Ethernet Controller XXV710-AM1 Firmware | ||
Intel Ethernet Controller x710-bm2 | <7.0 | |
Intel Ethernet Controller x710-bm2 firmware | ||
Intel Ethernet Controller XL710-BM1 Firmware | <7.0 | |
Intel Ethernet Controller 710-bm1 Firmware | ||
Intel Ethernet 700 Series software | <24.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-0140.
The title of the vulnerability is 'Buffer overflow in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an unauthenticated user to potentially enable an escalation of privilege via an adjacent access.'
The affected software is Intel Ethernet Controller X710-tm4 Firmware version up to exclusive 7.0, Intel Ethernet Controller X710-at2 Firmware version up to exclusive 7.0, Intel Ethernet Controller Xxv710-am2 Firmware version up to exclusive 7.0, Intel Ethernet Controller Xxv710-am1 Firmware version up to exclusive 7.0, Intel Ethernet Controller X710-bm2 Firmware version up to exclusive 7.0, and Intel Ethernet Controller 710-bm1 Firmware version up to exclusive 7.0.
The severity of the vulnerability is high with a CVSS score of 8.8.
To fix the vulnerability, update the firmware of the affected software to version 7.0 or higher.