HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2024-23499

CVSS 7.0v4.0pub. 2024-08-14upd. 2024-09-06

Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Intel Ethernet 800 Series Controllers Driver

    APP
    Intel
    < 28.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2024-23497CRITICAL9.3PL ✓same product

Out-of-bounds write w sterowniku Linux dla Intel Ethernet 800 Series — privilege escalation

CVE-2024-23981CRITICAL9.3PL ✓same product

Błąd wrap-around w sterowniku Intel Ethernet 800 — privilege escalation

CVE-2024-24986CRITICAL9.3PL ✓same product

Nieprawidłowa kontrola dostępu w sterowniku Intel Ethernet 800 Series — privilege escalation

CVE-2021-45046CRITICAL9.0⚠ KEVPL ✓same vendor

Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup

CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same vendor

Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup