Buffer overflow in Intel Ethernet 700 Series and Intel Ethernet 700 Series Controller Software - CVE-2019-0140
Published: November 25, 2019
Vulnerability identifier: #VU22947
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0140
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the target system.
The vulnerability exists due to a boundary error in firmware. An attacker on adjacent network can trigger memory corruption and escalate privileges on the target system.
Affected software
Intel Ethernet 700 Series
Intel Ethernet 700 Series Controller Software
EMC ECS
Intel Ethernet 700 Series Controller Software
EMC ECS
How to mitigate CVE-2019-0140
Install updates from vendor's website.
Intel Ethernet 700 Series - update to 7.0
Intel Ethernet 700 Series Controller Software - update to 24.0
EMC ECS - update to 3.5.0.1
Intel Ethernet 700 Series Controller Software - update to 24.0
EMC ECS - update to 3.5.0.1