MEDIUM · 5.5

CVE-2022-21793

Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare bef...

Vulnerability Description

Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 2.1.5.0 may allow an authenticated user to potentially enable a denial of service via local access.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
VmwareIxgben< 1.11.4.0
Intel82599 10 Gigabit Ethernet Controller-
IntelEthernet Controller X540-
IntelEthernet Controller X550-
IntelEthernet Controller X552-
VmwareI40En< 2.1.5.0
IntelEthernet Controller X710-
IntelEthernet Controller X722-
IntelEthernet Controller Xl710-
IntelEthernet Controller Xxv710-

References

FAQ

What is CVE-2022-21793?

CVE-2022-21793 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare bef...

How severe is CVE-2022-21793?

CVE-2022-21793 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-21793?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Ixgben, Intel 82599 10 Gigabit Ethernet Controller, Intel Ethernet Controller X540, Intel Ethernet Controller X550, Intel Ethernet Controller X552.