CVE-2019-0145
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.
Affected (11)
Products: Intel: Ethernet Controller X710 Tm4 Firmware, Ethernet Controller X710 At2 Firmware, Ethernet Controller Xxv710 Am2 Firmware, Ethernet Controller Xxv710 Am1 Firmware, Ethernet Controller X710 Bm2 Firmware, Ethernet Controller 710 Bm1 Firmware, Ethernet 700 Series Software · Linux: Linux Kernel
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0 |
| Running on/with | Platform Versions |
|---|---|
Intel Ethernet Controller X710 Tm4 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0 |
| Running on/with | Platform Versions |
|---|---|
Intel Ethernet Controller X710 At2 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0 |
| Running on/with | Platform Versions |
|---|---|
Intel Ethernet Controller Xxv710 Am2 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0 |
| Running on/with | Platform Versions |
|---|---|
Intel Ethernet Controller Xxv710 Am1 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0 |
| Running on/with | Platform Versions |
|---|---|
Intel Ethernet Controller X710 Bm2 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0 |
| Running on/with | Platform Versions |
|---|---|
Intel Ethernet Controller 710 Bm1 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 24.0 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.10 to 4.14.205 |
References (2)
Source: secure@intel.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.