Improper Initialization in Intel Ethernet I210 Controller - CVE-2020-0522

 

Improper Initialization in Intel Ethernet I210 Controller - CVE-2020-0522

Published: February 10, 2021


Vulnerability identifier: #VU50576
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0522
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper initialization in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters. A local user can run a specially crafted application to crash the system.


Affected software

Intel Ethernet I210 Controller
Precision 7920
OptiPlex XE3
OptiPlex 7071
OptiPlex 7070
OptiPlex 7060
Embedded Box PC 5000
Embedded Box PC 3000
Precision 3240 Compact
Precision 3430 XL
Precision 3431
Precision 3630
Precision 3630 XL
Precision 3930
Precision 5820
Precision 7820
Precision 3640 XE
OptiPlex 7080
ChengMing 3991
ChengMing 3990
Precision 3440
Precision 3640
BIG-IP

How to mitigate CVE-2020-0522

Install updates from vendor's website.

Intel Ethernet I210 Controller - update to 3.30

External References

Related Security Bulletins