CVE-2020-24496: Input Validation
Published Feb 17, 2021
·Updated
Insufficient input validation in the firmware for Intel(R) 722 Ethernet Controllers before version 1.4.3 may allow a privileged user to potentially enable denial of service via local access.
Affected Software
4 affected components
Intel Ethernet Network Adapter X722-da2 Firmware<1.4.3
Intel Ethernet Network Adapter X722-da2
Intel Ethernet Network Adapter X722-da4 Firmware<1.4.3
Intel Ethernet Network Adapter X722-da4
Remediation
Event History
Feb 17, 2021
CVE Published
via MITRE·01:42 PM
Data Sourced
via MITRE·01:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-24496?
CVE-2020-24496 has a medium severity rating due to insufficient input validation that can lead to denial of service.
2
How do I fix CVE-2020-24496?
To fix CVE-2020-24496, update the firmware of the Intel Ethernet Controllers to version 1.4.3 or later.
3
Which Intel products are affected by CVE-2020-24496?
CVE-2020-24496 affects the Intel Ethernet Network Adapter X722-DA2 and X722-DA4 firmware versions prior to 1.4.3.
4
Can CVE-2020-24496 be exploited remotely?
CVE-2020-24496 requires local access for exploitation, as it can potentially be triggered by a privileged user.
5
What issues can CVE-2020-24496 cause in a network environment?
CVE-2020-24496 may cause denial of service, impacting network availability if exploited.