CVE-2020-24503
Severity
5.5MEDIUM
EPSS
0.3%
top 51.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 17
Latest updateMay 24
Description
Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable information disclosure via local access.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages2 packages
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-c6gw-7j5j-4c6v: Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1↗2022-05-24
CVEList▶
CVE-2020-24503: Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1↗2021-02-17
OSV▶
CVE-2020-24503: Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1↗2021-02-17
📋Vendor Advisories
1Red Hat
▶