Improper access control in E810 Ethernet Controllers and Adapters - CVE-2022-28709
Published: August 15, 2022
Vulnerability identifier: #VU66497
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28709
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the firmware. A local administrator can bypass implemented security restrictions and perform a denial of service (DoS) attack.
Affected software
E810 Ethernet Controllers and Adapters
Avamar Data Store Gen5A
EMC Integrated Data Protection Appliance
Avamar Data Store Gen5A
EMC Integrated Data Protection Appliance
How to mitigate CVE-2022-28709
Install updates from vendor's website.
E810 Ethernet Controllers and Adapters - update to 1.6.2.9