SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-28376

Out-of-bounds read in the firmware for some Intel(R) E810 Ethernet Controllers and Adapters before version 1.7.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

MEDIUM 6.5EPSS 0.38%

Does this matter?

Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.

Description

Out-of-bounds read in the firmware for some Intel(R) E810 Ethernet Controllers and Adapters before version 1.7.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.38% probability · 32th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
intel/ethernet network adapter e810-2cqda2 firmware · intel/ethernet network adapter e810-cqda1 firmware · intel/ethernet network adapter e810-cqda1 for ocp firmware · intel/ethernet network adapter e810-cqda1 for ocp 3.0 firmware · intel/ethernet network adapter e810-cqda2 firmware · intel/ethernet network adapter e810-cqda2 for ocp 3.0 firmware · intel/ethernet network adapter e810-cqda2t firmware
Source
secure@intel.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.