Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-24502
HistoryFeb 17, 2021 - 12:00 a.m.

CVE-2020-24502

2021-02-1700:00:00
ubuntu.com
ubuntu.com
17
cve-2020-24502
intel ethernet e810
input validation
denial of service
linux
windows

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

12.6%

Improper input validation in some Intelยฎ Ethernet E810 Adapter drivers
for Linux before version 1.0.4 and before version 1.4.29.0 for Windows*,
may allow an authenticated user to potentially enable a denial of service
via local access.

Notes

Author Note
sbeattie these are Intelโ€™s out-of-tree drivers.

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

12.6%