CVE-2025-27243 Details
Description
Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
A denial-of-service vulnerability has been identified in the firmware for some Intel Ethernet Controller E810 models, prior to version cvl fw 1.7.8.x, within Ring 0: Bare Metal OS. This vulnerability arises from an out-of-bounds write, which may be exploited by a system software adversary with privileged user access. The attack, characterized by low complexity, can lead to a denial-of-service condition. The issue may occur through local access, without the need for user interaction, and requires no special internal knowledge.
Users are advised to update the firmware for Intel Ethernet Controller E810 to the latest version. Firmware updates are available for download from the Intel Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01171.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| intel ethernet controller | < 30.3 |
CPE
Remediation
| |
| intel ethernet network adapter e810-2cqda2 | All versions |
CPE
Remediation
| |
| intel ethernet network adapter e810-cqda1 | All versions |
CPE
Remediation
| |
| intel ethernet network adapter e810-cqda1 for ocp 3.0 | All versions |
CPE
Remediation
| |
| intel ethernet network adapter e810-cqda2 | All versions |
CPE
Remediation
| |
| intel ethernet network adapter e810-cqda2 for ocp 3.0 | All versions |
CPE
Remediation
| |
| intel ethernet network adapter e810-cqda2t | All versions |
CPE
Remediation
| |
| intel ethernet network adapter e810-xxvda2 | All versions |
CPE
Remediation
| |
| intel ethernet network adapter e810-xxvda2 for ocp 3.0 | All versions |
CPE
Remediation
| |
| intel ethernet network adapter e810-xxvda4 | All versions |
CPE
Remediation
| |
| intel ethernet network adapter e810-xxvda4 for ocp 3.0 | All versions |
CPE
Remediation
| |
| intel ethernet network adapter e810-xxvda4t | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | Initial Analysis | [email protected] |
| Feb 10, 2026 | New CVE Received | [email protected] |