CVE-2021-0004Improper Restriction of Operations within the Bounds of a Memory Buffer in Intel Ethernet Controller E810 Firmware

Severity
4.4MEDIUMNVD
EPSS
0.1%
top 82.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11
Latest updateMay 24

Description

Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow a privileged user to potentially enable denial of service via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6

Affected Packages1 packages

Also affects: Fedora 34

🔴Vulnerability Details

2
GHSA
GHSA-p85q-fm7j-ffmp: Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 12022-05-24
CVEList
CVE-2021-0004: Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 12021-08-11

💥Exploits & PoCs

1
Nuclei
Jitsi Meet - Remote Code Execution (Apache Log4j)

📋Vendor Advisories

2
VMware
VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2021-22040, CVE-2021-22041, CVE-2021-22042, CVE-2021-22043, CVE-2021-22050)2022-02-15
VMware
VMware vRealize Operations updates address Server Side Request Forgery and Arbitrary File Write vulnerabilities (CVE-2021-21975, CVE-2021-21983)2021-03-30
CVE-2021-0004 — Intel vulnerability | cvebase