Database/Control plane, storage & DevOps
Intel E810 NVM Update Utility: Insecure inherited permissions in the NVM update utility
Impact
Insecure inherited permissions in the NVM update utility - the tool you run to fix the NIC firmware issues above - let a local authenticated user escalate. Worth noting because the remediation tool being the vulnerability is a genuine operational trap when you push it fleet-wide under automation.
Who can reach it
Authenticated local user on a node where the utility is staged.
What to do
Use NVM Update Utility 4.60 or later, and check permissions on the staging directory your automation copies it into. Userspace tool, no reboot for the tool update itself.
References
Related entries
- Dell CloudLink (privilege escalation to database): A privileged user escalates laterally or reads the CloudLinkCVE-2025-46366 · Dell CloudLink (privilege escalation to database)Medium
- Dell CloudLink (risky cryptographic primitive): Use of a cryptographic primitive with a risky implementationCVE-2025-46424 · Dell CloudLink (risky cryptographic primitive)Medium
- JumpServer: Jinja2 injection in Applet Host fields executes commands on the control nodeCVE-2026-44845 · JumpServer (Applet Host deployment, Jinja2 template injection)Medium
- GlusterFS (glusterd management): An authenticated TLS client can use gluster cli --remote-host to add itself to theCVE-2018-10841 · GlusterFS (glusterd management)Medium
- Intel SPS (HECI subsystem compartmentalisation): Insufficient compartmentalisation in the HECI interfaceCVE-2021-0060 · Intel SPS (HECI subsystem compartmentalisation)Medium
- Dell CloudLink (cluster component exception handling): A highly privileged remote attacker performs unauthorizedCVE-2024-38482 · Dell CloudLink (cluster component exception handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.