Buffer overflow in Intel Ethernet 700 Series and Intel Ethernet 700 Series Controller Software - CVE-2019-0140

 

Buffer overflow in Intel Ethernet 700 Series and Intel Ethernet 700 Series Controller Software - CVE-2019-0140

Published: November 25, 2019


Vulnerability identifier: #VU22947
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0140
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the target system.

The vulnerability exists due to a boundary error in firmware. An attacker on adjacent network can trigger memory corruption and escalate privileges on the target system.



Affected software

Intel Ethernet 700 Series
Intel Ethernet 700 Series Controller Software
EMC ECS

How to mitigate CVE-2019-0140

Install updates from vendor's website.

Intel Ethernet 700 Series - update to 7.0
Intel Ethernet 700 Series Controller Software - update to 24.0
EMC ECS - update to 3.5.0.1

External References

Related Security Bulletins