Buffer overflow in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an unauthenticated user to potentially enable an escalation of privilege via an adjacent access.
References
Link | Resource |
---|---|
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00255.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
|
Information
Published : 2019-11-14 11:15
Updated : 2021-05-03 10:16
NVD link : CVE-2019-0140
Mitre link : CVE-2019-0140
JSON object : View
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Products Affected
intel
- ethernet_controller_x710-at2
- ethernet_controller_x710-bm2_firmware
- ethernet_controller_x710-tm4
- ethernet_controller_x710-tm4_firmware
- ethernet_controller_x710-bm2
- ethernet_700_series_software
- ethernet_controller_x710-at2_firmware
- ethernet_controller_xxv710-am1
- ethernet_controller_xxv710-am1_firmware
- ethernet_controller_xxv710-am2_firmware
- ethernet_controller_710-bm1
- ethernet_controller_xxv710-am2
- ethernet_controller_710-bm1_firmware