CVE-2019-0145

HIGH

Intel Ethernet Controller X710-tm4 Firmware < 7.0 - Buffer Overflow

Title source: rule
STIX 2.1

Description

Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0018
EPSS Percentile 39.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (8)
intel/ethernet_700_series_software < 24.0
intel/ethernet_controller_710-bm1_firmware < 7.0
intel/ethernet_controller_x710-at2_firmware < 7.0
intel/ethernet_controller_x710-bm2_firmware < 7.0
intel/ethernet_controller_x710-tm4_firmware < 7.0
intel/ethernet_controller_xxv710-am1_firmware < 7.0
intel/ethernet_controller_xxv710-am2_firmware < 7.0
linux/linux_kernel 4.6 - 4.9.244
Published Nov 14, 2019
Tracked Since Feb 18, 2026