Improper access control in Intel Ethernet I210 Controller - CVE-2020-0523

 

Improper access control in Intel Ethernet I210 Controller - CVE-2020-0523

Published: February 10, 2021


Vulnerability identifier: #VU50577
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0523
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper access restrictions in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters. A local privileged user can bypass implemented security restrictions and perform a denial of service (DoS) attack.


Affected software

Intel Ethernet I210 Controller
Precision 7920
OptiPlex XE3
OptiPlex 7071
OptiPlex 7070
OptiPlex 7060
Embedded Box PC 5000
Embedded Box PC 3000
Precision 3240 Compact
Precision 3430 XL
Precision 3431
Precision 3630
Precision 3630 XL
Precision 3930
Precision 5820
Precision 7820
Precision 3640 XE
OptiPlex 7080
ChengMing 3991
ChengMing 3990
Precision 3440
Precision 3640
BIG-IP

How to mitigate CVE-2020-0523

Install updates from vendor's website.

Intel Ethernet I210 Controller - update to 3.30

External References

Related Security Bulletins