GPU VulnDB

Database/Firmware, BMC & network fabric

Intel E810 Ethernet controller firmware (NVM < 1.4.1.13): Early-generation E810 firmware flaw (a second buffer overflow

CVE-2020-24500Firmware, BMC & network fabriccurated

Impact

Early-generation E810 firmware flaw (a second buffer overflow reachable by a privileged user) resulting in denial of service on the adapter. Relevant to any E810 adapter still on shipping-era NVM, which is common when NIC firmware was never brought into the patch pipeline.

Who can reach it

Varies by issue - the unauthenticated variant is reachable from the network, the others need privileged host access.

What to do

Fixed in the E810 NVM (adapter firmware) image. Deploy with Intel's NVM Update Utility, which needs a driver reload and a power cycle - not just a warm reboot - for the new image to take effect. Drain the node. Distinct from the ice driver updates: you need both, and they ship on different schedules. Target NVM 1.4.1.13 or later, but jump straight to a current image rather than the minimum fixed version.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.