Database/Firmware, BMC & network fabric
Intel E810 Ethernet Controller firmware: Buffer overflow in early E810 firmware, triggerable by an unauthenticated
Impact
Buffer overflow in early E810 firmware, triggerable by an unauthenticated adjacent attacker for denial of service. Worth carrying in an operator database because E810 cards that shipped in 2020-2021 server generations and were never NVM-updated are still in production fleets — NIC firmware is the layer operators most reliably forget to patch.
Who can reach it
Unauthenticated, adjacent — same L2 segment.
What to do
Flash E810 firmware to 1.4.1.13 or later. Cold power cycle. Practically: audit your fleet's NVM versions first (ethtool -i reports the firmware-version string) — most operators discover a wide spread of versions and should batch the whole update rather than chase individual CVEs.
References
Related entries
- Intel E810 Ethernet Controller firmware: Out-of-bounds read in E810 firmware reachable from an adjacentCVE-2023-28376 · Intel E810 Ethernet Controller firmwareMedium
- Intel processors (shared resource isolation): Improper isolation of shared processor resources allowing informationCVE-2020-24511 · Intel processors (shared resource isolation)Medium
- Intel Atom processors (domain-bypass transient execution): A domain-bypass transient execution flaw on Atom partsCVE-2020-24513 · Intel Atom processors (domain-bypass transient execution)Medium
- Intel SGX DCAP (datacenter attestation primitives): An improper conditions check in DCAP lets an unauthenticatedCVE-2020-8766 · Intel SGX DCAP (datacenter attestation primitives)Medium
- Intel Ethernet 800 Series Controller firmware: Out-of-bounds read in 800-series (E810 family) adapter firmwareCVE-2021-0009 · Intel Ethernet 800 Series Controller firmwareMedium
- AMD processors - transient execution beyond unconditional direct branches: Some AMD CPUs transiently executeCVE-2021-26341 · AMD processors - transient execution beyond unconditional direct branchesMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.