CVE-2020-24503

Severity
5.5MEDIUM
EPSS
0.3%
top 51.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 17
Latest updateMay 24

Description

Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c6gw-7j5j-4c6v: Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 12022-05-24
CVEList
CVE-2020-24503: Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 12021-02-17
OSV
CVE-2020-24503: Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 12021-02-17

📋Vendor Advisories

1
Red Hat
kernel: Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers2021-02-17
CVE-2020-24503 (MEDIUM CVSS 5.5) | Insufficient access control in some | cvebase.io