CVE-2025-32003

Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, cpk 1.3.7 within Ring 0: Bare Metal OS may allow a denial of service. Network adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:intel:ethernet_controller:*:*:*:*:*:*:*:*
OR cpe:2.3:h:intel:ethernet_network_adapter_e810-2cqda2:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-cqda1:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-cqda1_for_ocp_3.0:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-cqda2:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-cqda2_for_ocp_3.0:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-cqda2t:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-xxvda2:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-xxvda2_for_ocp_3.0:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-xxvda4:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-xxvda4_for_ocp_3.0:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-xxvda4t:-:*:*:*:*:*:*:*

History

17 Mar 2026, 15:44

Type Values Removed Values Added
First Time Intel ethernet Network Adapter E810-cqda2t
Intel ethernet Network Adapter E810-xxvda4t
Intel
Intel ethernet Network Adapter E810-xxvda2
Intel ethernet Network Adapter E810-xxvda2 For Ocp 3.0
Intel ethernet Network Adapter E810-2cqda2
Intel ethernet Network Adapter E810-cqda2
Intel ethernet Network Adapter E810-xxvda4
Intel ethernet Network Adapter E810-cqda1 For Ocp 3.0
Intel ethernet Network Adapter E810-cqda1
Intel ethernet Network Adapter E810-cqda2 For Ocp 3.0
Intel ethernet Controller
Intel ethernet Network Adapter E810-xxvda4 For Ocp 3.0
CPE cpe:2.3:a:intel:ethernet_controller:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-cqda2t:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-xxvda2:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-cqda2:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-cqda1_for_ocp_3.0:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-xxvda2_for_ocp_3.0:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-xxvda4:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-cqda1:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-xxvda4_for_ocp_3.0:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-2cqda2:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-xxvda4t:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ethernet_network_adapter_e810-cqda2_for_ocp_3.0:-:*:*:*:*:*:*:*
Summary
  • (es) Lectura fuera de límites en el firmware para algunos adaptadores de red Ethernet Intel(R) 100GbE E810 anteriores a la versión cvl fw 1.7.6, cpk 1.3.7 dentro del Anillo 0: el SO Bare Metal puede permitir una denegación de servicio. Un adversario de red con un usuario autenticado combinado con un ataque de baja complejidad puede habilitar la denegación de servicio. Este resultado puede ocurrir potencialmente a través del acceso a la red cuando los requisitos de ataque están presentes con conocimiento interno especial y no requiere interacción del usuario. La vulnerabilidad potencial puede impactar la confidencialidad (ninguna), la integridad (ninguna) y la disponibilidad (alta) del sistema vulnerable, lo que resulta en impactos subsiguientes en la confidencialidad (ninguna), la integridad (ninguna) y la disponibilidad (ninguna) del sistema.
References () https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01171.html - () https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01171.html - Vendor Advisory

10 Feb 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 17:16

Updated : 2026-03-17 15:44


NVD link : CVE-2025-32003

Mitre link : CVE-2025-32003

CVE.ORG link : CVE-2025-32003


JSON object : View

Products Affected

intel

  • ethernet_network_adapter_e810-xxvda4_for_ocp_3.0
  • ethernet_network_adapter_e810-cqda2_for_ocp_3.0
  • ethernet_network_adapter_e810-xxvda2
  • ethernet_network_adapter_e810-xxvda2_for_ocp_3.0
  • ethernet_network_adapter_e810-xxvda4
  • ethernet_controller
  • ethernet_network_adapter_e810-cqda1_for_ocp_3.0
  • ethernet_network_adapter_e810-xxvda4t
  • ethernet_network_adapter_e810-cqda2t
  • ethernet_network_adapter_e810-cqda2
  • ethernet_network_adapter_e810-cqda1
  • ethernet_network_adapter_e810-2cqda2
CWE
CWE-125

Out-of-bounds Read