GPU VulnDB

Database/Firmware, BMC & network fabric

Intel Ethernet 800 Series Controller firmware: Out-of-bounds read in 800-series (E810 family) adapter firmware

CVE-2021-0009Firmware, BMC & network fabriccurated

Impact

Out-of-bounds read in 800-series (E810 family) adapter firmware, reachable by an unauthenticated user, causing denial of service. Listed separately from the later E810 issues because the fixed version target is different (1.5.3.0), so a fleet standardised on a mid-2021 NVM image is exposed to this one even if it is patched for the 2023-2025 batch.

Who can reach it

Unauthenticated, over the network to the adapter.

What to do

Flash 800-series firmware to 1.5.3.0 or later; cold power cycle. In practice, set a single fleet-wide minimum NVM version well above all of these and enforce it in provisioning, rather than tracking each CVE's individual threshold.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.