Database/Firmware, BMC & network fabric
Intel Ethernet Controller E810 (100GbE) firmware: Uncaught exception in 100GbE E810 firmware, reachable from privileged
CVSS 6.0CVE-2025-24851Firmware, BMC & network fabricINTEL-SA-01171curated
Impact
Uncaught exception in 100GbE E810 firmware, reachable from privileged host software, causing denial of service. Ships in the same advisory as the out-of-bounds write, so a single NVM update fixes both — worth listing separately so operators tracking by CVE do not think they are done after one.
Who can reach it
Privileged local software on the host.
What to do
Same NVM update as CVE-2025-27243 — E810 firmware cvl fw 1.7.8.x or later, cold power cycle. One flash, two CVEs.
References
Related entries
- Intel Ethernet Controller E810 firmware: Out-of-bounds write inside E810 firmware, reachable from a privileged Ring-0CVE-2025-27243 · Intel Ethernet Controller E810 firmwareMedium
- HPE ProLiant RL300 Gen11 (UEFI firmware, out-of-bounds read): Out-of-bounds reads in the UEFI firmware of the ProLiantCVE-2025-37149 · HPE ProLiant RL300 Gen11 (UEFI firmware, out-of-bounds read)Medium
- NVIDIA DGX Spark: out-of-bounds read in standalone MM firmware discloses information across a scope boundaryCVE-2026-24225 · NVIDIA DGX Spark (standalone MM firmware)Medium
- NVIDIA DGX Spark: UEFI administrator password protection can be bypassed by a privileged local userCVE-2026-47624 · NVIDIA DGX Spark (UEFI administrator password protection)Medium
- Arista EOS: gNPSI client credentials can be written in clear text to accounting logsCVE-2026-73457 · Arista EOS gNPSI (client credentials in accounting logs)Medium
- Arista EOS: gNSI authz policy rotation can fail silently, leaving revoked gRPC access in placeCVE-2026-73463 · Arista EOS gNSI Authz service (policy rotation race with multiple gNSI transports)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.