First published: Wed Feb 17 2021(Updated: )
Description: Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable information disclosure via local access. References: <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00462.html">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00462.html</a>
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:4.18.0-348.rt7.130.el8 | 0:4.18.0-348.rt7.130.el8 |
redhat/kernel | <0:4.18.0-348.el8 | 0:4.18.0-348.el8 |
Intel Ethernet network Adapter E810 firmware Linux | <1.0.4 | |
Intel Ethernet Network Adapter E810-CQDA1 for OCP | ||
Intel Ethernet Network Adapter E810-CQDA1 | ||
Intel Ethernet Network Adapter E810-CQDA1 for OCP | ||
Intel Ethernet Network Adapter E810-CQDA2 for OCP 3.0 | ||
Intel Ethernet Network Controllers and Adapters E810 Series | ||
Intel Ethernet Network Adapter E810-XXVDA2 for OCP | ||
Intel Ethernet Network Adapter E810-XXVDA2 | ||
Intel Ethernet Network Adapter E810-XXVDA2 | ||
Intel Ethernet Network Controllers and Adapters E810 Series |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24503 has a medium severity rating due to insufficient access control allowing information disclosure.
To fix CVE-2020-24503, update the Intel Ethernet E810 Adapter drivers to version 1.0.4 or later.
CVE-2020-24503 affects Intel Ethernet E810 Adapter drivers for Linux prior to version 1.0.4.
CVE-2020-24503 may allow authenticated users to disclose sensitive information through local access.
Yes, a patch is available in the updates for the Intel Ethernet E810 Adapter drivers starting from version 1.0.4.