CVE-2020-24502

Severity
5.5MEDIUM
EPSS
0.2%
top 58.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 17
Latest updateMay 24

Description

Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 and before version 1.4.29.0 for Windows*, may allow an authenticated user to potentially enable a denial of service via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5intel(r)_ethernet_e810_adapter_drivers_for_linux_before_version_1.0.4_andbefore version 1.0.4 and before version 1.4.29.0 for Windows

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5xc2-h74h-475j: Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 12022-05-24
OSV
CVE-2020-24502: Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 12021-02-17
CVEList
CVE-2020-24502: Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 12021-02-17

📋Vendor Advisories

1
Red Hat
kernel: Improper input validation in some Intel(R) Ethernet E810 Adapter drivers2021-02-17
CVE-2020-24502 (MEDIUM CVSS 5.5) | Improper input validation in some I | cvebase.io