Database/Firmware, BMC & network fabric
Intel Ethernet 800 Series Controller firmware: Out-of-bounds read in 800-series (E810 family) adapter firmware
Impact
Out-of-bounds read in 800-series (E810 family) adapter firmware, reachable by an unauthenticated user, causing denial of service. Listed separately from the later E810 issues because the fixed version target is different (1.5.3.0), so a fleet standardised on a mid-2021 NVM image is exposed to this one even if it is patched for the 2023-2025 batch.
Who can reach it
Unauthenticated, over the network to the adapter.
What to do
Flash 800-series firmware to 1.5.3.0 or later; cold power cycle. In practice, set a single fleet-wide minimum NVM version well above all of these and enforce it in provisioning, rather than tracking each CVE's individual threshold.
References
Related entries
- AMD processors - transient execution beyond unconditional direct branches: Some AMD CPUs transiently executeCVE-2021-26341 · AMD processors - transient execution beyond unconditional direct branchesMedium
- InsydeH2O: BIOS user and administrator password hashes exposed in runtime-readable UEFI variablesCVE-2021-43613 · Insyde InsydeH2O SysPasswordDxe (BIOS password hashes in runtime UEFI variables)Medium
- Lanner IAC-AST2500A BMC firmware: The attacker rewrites who is permitted to use KVM and virtual media on the BMCCVE-2021-44776 · Lanner IAC-AST2500A BMC firmwareMedium
- AMD SEV / SEV-ES / SEV-SNP - ciphertext observability: SEV encrypts guest memory deterministically per physicalCVE-2021-46744 · AMD SEV / SEV-ES / SEV-SNP - ciphertext observabilityMedium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): The transmit health reporter's dump callback casts itsCVE-2021-46931 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)Medium
- Linux kernel Soft-RoCE completer (rdma_rxe, invalid lkey handling in atomic operations): The local key is the RDMACVE-2021-47076 · Linux kernel Soft-RoCE completer (rdma_rxe, invalid lkey handling in atomic operations)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.