Intel Ethernet Connection E825-C Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in the firmware for some Intel Ethernet Connection E825-C adapters, prior to version NVM 3.84. The issue arises from an exposed ioctl with inadequate access control, allowing a system software adversary with privileged user rights to disrupt service. This vulnerability can be exploited through local access, without special internal knowledge or user interaction, under certain attack conditions.
Impact
Exploitation of this vulnerability can lead to a denial-of-service condition, causing a significant disruption in network availability.
Remediation
Users are advised to update the firmware to version 3.84 or later. The latest firmware can be downloaded from the Intel Ethernet Adapters 800 Series Controllers support page.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
