MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2025-27535

CVSS 5.6v4.0pub. 2026-02-10upd. 2026-03-17

Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before version NVM ver. 3.84 within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS Vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Intel Ethernet Connection E825 C

    HW
    Intel
    all versions
  • Intel Ethernet Controller

    APP
    Intel
    < 30.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2025-24851MEDIUM6.7same product

Nieobsłużony wyjątek w firmware'u algunych kontrolerów Ethernet 100GbE Intel(R) E810 przed wersją cvl fw 1.7.8...

CVE-2025-27243MEDIUM6.7same product

Out-of-bounds write w oprogramowaniu układu Intel(R) Ethernet Controller E810 przed wersją cvl fw 1.7.8.x w Ri...

CVE-2025-32003MEDIUM6.0same product

Out-of-bounds read w oprogramowaniu sprzętowym niektórych 100GbE Intel(R) Ethernet Network Adapter E810 przed ...

CVE-2021-45046CRITICAL9.0⚠ KEVPL ✓same vendor

Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup

CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same vendor

Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup