First published: Thu Nov 14 2019(Updated: )
Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Ethernet Controller x710-tm4 | <2.8.43 | |
Intel Ethernet Controller x710-tm4 | ||
Intel Ethernet Controller x710-at2 | <2.8.43 | |
Intel Ethernet Controller x710-at2 | ||
Intel Ethernet Controller XXV710-AM2 | <2.8.43 | |
Intel Ethernet Controller xxv710-am2 firmware | ||
Intel Ethernet Controller XXV710-AM1 | <2.8.43 | |
Intel Ethernet Controller XXV710-AM1 Firmware | ||
Intel Ethernet Controller x710-bm2 | <2.8.43 | |
Intel Ethernet Controller x710-bm2 firmware | ||
Intel Ethernet Controller XL710-BM1 Firmware | <2.8.43 | |
Intel Ethernet Controller 710-bm1 Firmware | ||
Intel Ethernet 700 Series software | <24.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0149 is a vulnerability in the i40e driver for Intel Ethernet 700 Series Controllers.
An authenticated user can potentially enable a denial of service via local access.
Versions before 2.8.43 of Intel Ethernet 700 Series Controllers are affected.
CVE-2019-0149 has a severity rating of medium (5.5).
You can find more information about CVE-2019-0149 at Intel's Security Center advisory page: [Link](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00255.html)