CVE-2023-28376

Out-of-bounds read in the firmware for some Intel(R) E810 Ethernet Controllers and Adapters before version 1.7.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
intelethernet_network_adapter_e810-2cqda2_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda1_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda1_for_ocp_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda1_for_ocp_3.0_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda2_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda2_for_ocp_3.0_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda2t_firmware
𝑥
< 1.7.1
𝑥
= Vulnerable software versions