CVE-2025-24851: Medium severity Intel Ethernet Controller E810 vulnerability
Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24851?
CVE-2025-24851 is classified as a denial of service vulnerability.
How do I fix CVE-2025-24851?
To fix CVE-2025-24851, update the Intel Ethernet Controller E810 firmware to version cvl fw 1.7.8.x or later.
What does CVE-2025-24851 affect?
CVE-2025-24851 affects the Intel Ethernet Controller E810 models before firmware version cvl fw 1.7.8.x.
What is the potential impact of CVE-2025-24851?
The potential impact of CVE-2025-24851 is denial of service, which can disrupt normal operations.
Who is at risk from CVE-2025-24851?
Systems that use the affected Intel Ethernet Controller E810 firmware are at risk from CVE-2025-24851.