GPU VulnDB

Database/Firmware, BMC & network fabric

Intel E810 Ethernet controller firmware: privileged-local buffer overflows allow denial of service

CVSS 4.4CVE-2020-24498Firmware, BMC & network fabric+1 more CVEscurated

Impact

A privileged local user can trigger a buffer overflow in E810 adapter firmware and knock the NIC out of service. Intel split this across 2 CVE ids in INTEL-SA-00456 without distinguishing the two overflows; both affect any E810 adapter still running shipping-era NVM, which is common where NIC firmware was never brought into the patch pipeline.

Who can reach it

Varies by issue - the unauthenticated variant is reachable from the network, the others need privileged host access.

What to do

One NVM (adapter firmware) update clears both ids. Deploy with Intel's NVM Update Utility, which needs a driver reload and a power cycle - not just a warm reboot - for the new image to take effect, so drain the node first. Distinct from the ice driver updates: you need both, and they ship on different schedules. Target NVM 1.4.1.13 or later, but jump straight to a current image rather than the minimum fixed version.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2020-24500

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.