CVE-2023-28376

Out-of-bounds read in the firmware for some Intel(R) E810 Ethernet Controllers and Adapters before version 1.7.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
intelCNA
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 24%
VendorProductVersion
intelethernet_network_adapter_e810-2cqda2_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda1_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda1_for_ocp_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda1_for_ocp_3.0_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda2_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda2_for_ocp_3.0_firmware
𝑥
< 1.7.1
intelethernet_network_adapter_e810-cqda2t_firmware
𝑥
< 1.7.1
𝑥
= Vulnerable software versions