Intel Ethernet Network Adapter E810 Out-of-Bounds Read Vulnerability Allowing Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in the firmware for some 100GbE Intel Ethernet Network Adapter E810 models, prior to version cvl fw 1.7.6 and cpk 1.3.7. The issue arises from an out-of-bounds read within Ring 0: Bare Metal OS, which may be exploited by a network adversary with authenticated user access. This low-complexity attack could lead to a denial-of-service condition, potentially occurring via network access when specific internal knowledge is available, and requires no user interaction.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, causing the affected system to become unresponsive or unavailable.

Remediation

Users are advised to update the firmware for the Intel Ethernet Network Adapter E810 to version cvl fw 1.7.6 or later. The latest firmware updates can be downloaded from the Intel Ethernet Adapters 800 Series Controllers support page.

Added: Feb 10, 2026, 5:27 PM
Updated: Feb 11, 2026, 2:25 AM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
3.3
exploitability
2.9
remediation
7.7
relevance
2.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.