Database/Firmware, BMC & network fabric
Intel Ethernet Controller E810 firmware: Out-of-bounds write inside E810 firmware, reachable from a privileged Ring-0
Impact
Out-of-bounds write inside E810 firmware, reachable from a privileged Ring-0 software adversary on the host, causing denial of service. The important framing for an operator is that this is a **write** primitive into NIC firmware from the host: on a bare-metal rental where the tenant has kernel privilege, the boundary between 'a tenant had root on the node' and 'the NIC's firmware state was modified' is exactly what this class of bug erodes. The published impact is DoS, but the primitive is the concern.
Who can reach it
Privileged local software on the host (Ring 0 / bare-metal OS). Any tenant with root on a rented bare-metal node qualifies.
What to do
Flash E810 firmware to cvl fw 1.7.8.x or later; cold power cycle. Beyond the patch: if you rent bare metal, reflash NIC firmware from a known-good image at tenant handoff and verify the version afterwards, because a patched-but-unverified NIC is not a clean NIC.
References
Related entries
- Intel Ethernet Controller E810 firmware: An unauthenticated attacker on the network can take an E810 NIC out of serviceCVE-2024-24983 · Intel Ethernet Controller E810 firmwareMedium
- HPE ProLiant RL300 Gen11 (UEFI firmware, out-of-bounds read): Out-of-bounds reads in the UEFI firmware of the ProLiantCVE-2025-37149 · HPE ProLiant RL300 Gen11 (UEFI firmware, out-of-bounds read)Medium
- NVIDIA DGX Spark: out-of-bounds read in standalone MM firmware discloses information across a scope boundaryCVE-2026-24225 · NVIDIA DGX Spark (standalone MM firmware)Medium
- NVIDIA DGX Spark: UEFI administrator password protection can be bypassed by a privileged local userCVE-2026-47624 · NVIDIA DGX Spark (UEFI administrator password protection)Medium
- Arista EOS: gNPSI client credentials can be written in clear text to accounting logsCVE-2026-73457 · Arista EOS gNPSI (client credentials in accounting logs)Medium
- Arista EOS: gNSI authz policy rotation can fail silently, leaving revoked gRPC access in placeCVE-2026-73463 · Arista EOS gNSI Authz service (policy rotation race with multiple gNSI transports)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.