CVE-2022-37341

Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H
intelCNA
7.2 HIGH
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
intelethernet_network_adapter_xl710-qda1_for_open_compute_project
𝑥
< 29.0.1
intelethernet_network_adapter_x710-t4l_for_ocp_3.0
𝑥
< 29.0.1
intelethernet_network_adapter_x710-t4l
𝑥
< 29.0.1
intelethernet_network_adapter_e810-xxvda2_for_ocp_3.0
𝑥
< 29.0.1
intelethernet_network_adapter_e810-xxvda4
𝑥
< 29.0.1
intelethernet_network_adapter_e810-2cqda2
𝑥
< 29.0.1
intelethernet_network_adapter_xl710-qda2_for_open_compute_project
𝑥
< 29.0.1
intelethernet_network_adapter_e810-xxvda2
𝑥
< 29.0.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux-firmware
noble
needs-triage
mantic
ignored
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
needs-triage