CVE-2021-0004 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Intel Ethernet Controller E810 Firmware
Severity
4.4MEDIUMNVD
EPSS
0.1%
top 82.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 11
Latest updateMay 24
Description
Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow a privileged user to potentially enable denial of service via local access.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6
Affected Packages1 packages
Also affects: Fedora 34
🔴Vulnerability Details
2GHSA▶
GHSA-p85q-fm7j-ffmp: Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1↗2022-05-24
CVEList▶
CVE-2021-0004: Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1↗2021-08-11
💥Exploits & PoCs
1Nuclei▶
Jitsi Meet - Remote Code Execution (Apache Log4j)
📋Vendor Advisories
2VMware▶
VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2021-22040, CVE-2021-22041, CVE-2021-22042, CVE-2021-22043, CVE-2021-22050)↗2022-02-15
VMware▶
VMware vRealize Operations updates address Server Side Request Forgery and Arbitrary File Write vulnerabilities (CVE-2021-21975, CVE-2021-21983)↗2021-03-30