First published: Wed Feb 17 2021(Updated: )
Insufficient access control in the firmware for the Intel(R) 722 Ethernet Controllers before version 1.5 may allow a privileged user to potentially enable a denial of service via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Ethernet network Adapter x722da2 firmware | <1.5 | |
Intel Ethernet Network Adapter X722-DA2 | ||
Intel Ethernet Network Adapter X722-DA4 | <1.5 | |
Intel Ethernet Network Adapter X722-DA4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24492 is classified as a medium severity vulnerability due to insufficient access control that may allow a denial of service.
To mitigate CVE-2020-24492, update the firmware for Intel Ethernet Controllers to version 1.5 or later.
CVE-2020-24492 affects the Intel Ethernet Network Adapter X722-DA2 and X722-DA4 with firmware versions prior to 1.5.
A non-privileged user cannot exploit CVE-2020-24492 as it requires privileged access to enable a denial of service.
There is no known workaround for CVE-2020-24492; the recommended action is to upgrade the firmware.