CVE-2023-28376

EUVD-2023-32072
Out-of-bounds read in the firmware for some Intel(R) E810 Ethernet Controllers and Adapters before version 1.7.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
intelCNA
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
Affected Products (NVD)
VendorProductVersion
intelethernet_network_adapter_e810-2cqda2_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda1_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda1_for_ocp_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda1_for_ocp_3.0_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda2_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda2_for_ocp_3.0_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda2t_firmware
𝑥
< 1.7.1
𝑥
= Vulnerable software versions