CVE-2019-0140: Buffer Overflow
Buffer overflow in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an unauthenticated user to potentially enable an escalation of privilege via an adjacent access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-0140.
What is the title of the vulnerability?
The title of the vulnerability is 'Buffer overflow in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an unauthenticated user to potentially enable an escalation of privilege via an adjacent access.'
What is the affected software?
The affected software is Intel Ethernet Controller X710-tm4 Firmware version up to exclusive 7.0, Intel Ethernet Controller X710-at2 Firmware version up to exclusive 7.0, Intel Ethernet Controller Xxv710-am2 Firmware version up to exclusive 7.0, Intel Ethernet Controller Xxv710-am1 Firmware version up to exclusive 7.0, Intel Ethernet Controller X710-bm2 Firmware version up to exclusive 7.0, and Intel Ethernet Controller 710-bm1 Firmware version up to exclusive 7.0.
What is the severity of the vulnerability?
The severity of the vulnerability is high with a CVSS score of 8.8.
How can I fix the vulnerability?
To fix the vulnerability, update the firmware of the affected software to version 7.0 or higher.