CVE-2025-32003: Medium severity Intel Ethernet Network Adapter E810 vulnerability
Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, cpk 1.3.7 within Ring 0: Bare Metal OS may allow a denial of service. Network adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32003?
The severity of CVE-2025-32003 is classified as high due to the potential for denial of service.
How do I fix CVE-2025-32003?
To fix CVE-2025-32003, upgrade the firmware of the Intel Ethernet Network Adapter E810 to version cvl fw 1.7.6 or later.
What systems are affected by CVE-2025-32003?
CVE-2025-32003 affects the Intel Ethernet Network Adapter E810 prior to firmware version cvl fw 1.7.6.
What type of attack does CVE-2025-32003 facilitate?
CVE-2025-32003 may enable denial of service through an out-of-bounds read vulnerability.
Who is at risk from CVE-2025-32003?
Network adversaries with authenticated user access are at risk of exploiting CVE-2025-32003 for denial of service attacks.