Incorrect default permissions in Intel Ethernet I210 Controller - CVE-2020-0524

 

Incorrect default permissions in Intel Ethernet I210 Controller - CVE-2020-0524

Published: February 10, 2021


Vulnerability identifier: #VU50578
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0524
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to incorrect default permissions in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters. A local user can perform a denial of service attack.


Affected software

Intel Ethernet I210 Controller
Precision 7920
OptiPlex XE3
OptiPlex 7071
OptiPlex 7070
OptiPlex 7060
Embedded Box PC 5000
Embedded Box PC 3000
Precision 3240 Compact
Precision 3430 XL
Precision 3431
Precision 3630
Precision 3630 XL
Precision 3930
Precision 5820
Precision 7820
Precision 3640 XE
OptiPlex 7080
ChengMing 3991
ChengMing 3990
Precision 3440
Precision 3640
BIG-IP

How to mitigate CVE-2020-0524

Install updates from vendor's website.

Intel Ethernet I210 Controller - update to 3.30

External References

Related Security Bulletins