4.4

CVE-2020-24505

Insufficient input validation in the firmware for the Intel(R) 700-series of Ethernet Controllers before version 7.3 may allow a privileged user to potentially enable denial of service via local access.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IntelEthernet Network Adapter 700 Firmware Version < 7.3
   IntelEthernet Network Adapter V710-at2 Version-
   IntelEthernet Network Adapter X710-am2 Version-
   IntelEthernet Network Adapter X710-at2 Version-
   IntelEthernet Network Adapter X710-bm2 Version-
   IntelEthernet Network Adapter X710-da2 Version-
   IntelEthernet Network Adapter X710-da2 For Ocp Version-
   IntelEthernet Network Adapter X710-da2 For Ocp 3.0 Version-
   IntelEthernet Network Adapter X710-da4 Version-
   IntelEthernet Network Adapter X710-da4 For Ocp 3.0 Version-
   IntelEthernet Network Adapter X710-t2l Version-
   IntelEthernet Network Adapter X710-t2l For Ocp 3.0 Version-
   IntelEthernet Network Adapter X710-t4 Version-
   IntelEthernet Network Adapter X710-t4l Version-
   IntelEthernet Network Adapter X710-t4l For Ocp 3.0 Version-
   IntelEthernet Network Adapter X710-tm4 Version-
   IntelEthernet Network Adapter X722-da2 Version-
   IntelEthernet Network Adapter X722-da4 Version-
   IntelEthernet Network Adapter Xl710-am1 Version-
   IntelEthernet Network Adapter Xl710-am2 Version-
   IntelEthernet Network Adapter Xl710-bm1 Version-
   IntelEthernet Network Adapter Xl710-bm2 Version-
   IntelEthernet Network Adapter Xl710-qda1 Version-
   IntelEthernet Network Adapter Xl710-qda1 For Open Compute Project Version-
   IntelEthernet Network Adapter Xl710-qda2 For Open Compute Project Version-
   IntelEthernet Network Adapter Xlk710-qda2 Version-
   IntelEthernet Network Adapter Xxv710-am1 Version-
   IntelEthernet Network Adapter Xxv710-am2 Version-
   IntelEthernet Network Adapter Xxv710-da1 Version-
   IntelEthernet Network Adapter Xxv710-da1 For Ocp Version-
   IntelEthernet Network Adapter Xxv710-da2 Version-
   IntelEthernet Network Adapter Xxv710-da2t Version-
   IntelEthernet Network Adapter Xxv710-dax For Ocp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.14
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.