Improper access control in Intel Ethernet 700 Series and Intel Ethernet 700 Series Controller Software - CVE-2019-0139

 

Improper access control in Intel Ethernet 700 Series and Intel Ethernet 700 Series Controller Software - CVE-2019-0139

Published: November 25, 2019


Vulnerability identifier: #VU22946
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0139
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A local user can bypass implemented security restrictions and enable an escalation of privilege, denial of service or information disclosure.


Affected software

Intel Ethernet 700 Series
Intel Ethernet 700 Series Controller Software

How to mitigate CVE-2019-0139

Install updates from vendor's website.

Intel Ethernet 700 Series - update to 7.0
Intel Ethernet 700 Series Controller Software - update to 24.0

External References

Related Security Bulletins