CVE-2019-0140

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
14/11/2019
Last modified:
03/05/2021

Description

Buffer overflow in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an unauthenticated user to potentially enable an escalation of privilege via an adjacent access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intel:ethernet_controller_x710-tm4_firmware:*:*:*:*:*:*:*:* 7.0 (excluding)
cpe:2.3:h:intel:ethernet_controller_x710-tm4:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:ethernet_controller_x710-at2_firmware:*:*:*:*:*:*:*:* 7.0 (excluding)
cpe:2.3:h:intel:ethernet_controller_x710-at2:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:ethernet_controller_xxv710-am2_firmware:*:*:*:*:*:*:*:* 7.0 (excluding)
cpe:2.3:h:intel:ethernet_controller_xxv710-am2:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:ethernet_controller_xxv710-am1_firmware:*:*:*:*:*:*:*:* 7.0 (excluding)
cpe:2.3:h:intel:ethernet_controller_xxv710-am1:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:ethernet_controller_x710-bm2_firmware:*:*:*:*:*:*:*:* 7.0 (excluding)
cpe:2.3:h:intel:ethernet_controller_x710-bm2:-:*:*:*:*:*:*:*
cpe:2.3:o:intel:ethernet_controller_710-bm1_firmware:*:*:*:*:*:*:*:* 7.0 (excluding)
cpe:2.3:h:intel:ethernet_controller_710-bm1:-:*:*:*:*:*:*:*
cpe:2.3:a:intel:ethernet_700_series_software:*:*:*:*:*:*:*:* 24.0 (excluding)