// For flags

CVE-2015-1142857

 

Severity Score

8.6
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

On multiple SR-IOV cars it is possible for VF's assigned to guests to send ethernet flow control pause frames via the PF. This includes Linux kernel ixgbe driver before commit f079fa005aae08ee0e1bc32699874ff4f02e11c1, the Linux Kernel i40e/i40evf driver before e7358f54a3954df16d4f87e3cad35063f1c17de5 and the DPDK before commit 3f12b9f23b6499ff66ec8b0de941fb469297e5d0, additionally Multiple vendor NIC firmware is affected.

En múltiples tarjetas SR-IOV, es posible que los VF asignados a los clientes envíen frames de pausa de control de flujo ethernet mediante el PF. Esto incluye el controlador ixgbe del kernel de Linux con commit con ID anterior a f079fa005aae08ee0e1bc32699874ff4f02e11c1, el controlador del kernel de Linux i40e/i40evf anterior a e7358f54a3954df16d4f87e3cad35063f1c17de5 y el DPDK anterior al commit con ID 3f12b9f23b6499ff66ec8b0de941fb469297e5d0. Además, también se ha visto afectado el firmware NIC de múltiples fabricantes.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-01-23 CVE Reserved
  • 2018-01-23 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-254: 7PK - Security Features
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Intel
Search vendor "Intel"
X710 Firmware
Search vendor "Intel" for product "X710 Firmware"
--
Affected
in Intel
Search vendor "Intel"
X710
Search vendor "Intel" for product "X710"
--
Safe
Intel
Search vendor "Intel"
82599 Firmware
Search vendor "Intel" for product "82599 Firmware"
--
Affected
in Intel
Search vendor "Intel"
82599
Search vendor "Intel" for product "82599"
--
Safe
Intel
Search vendor "Intel"
X540 Firmware
Search vendor "Intel" for product "X540 Firmware"
--
Affected
in Intel
Search vendor "Intel"
X540
Search vendor "Intel" for product "X540"
--
Safe
Intel
Search vendor "Intel"
I350 Firmware
Search vendor "Intel" for product "I350 Firmware"
--
Affected
in Intel
Search vendor "Intel"
I350
Search vendor "Intel" for product "I350"
--
Safe
Intel
Search vendor "Intel"
82576 Firmware
Search vendor "Intel" for product "82576 Firmware"
--
Affected
in Intel
Search vendor "Intel"
82576
Search vendor "Intel" for product "82576"
--
Safe
Linux
Search vendor "Linux"
Linux Kernel Ixgbe
Search vendor "Linux" for product "Linux Kernel Ixgbe"
--
Affected
Linux
Search vendor "Linux"
Linux Kernel I40e\/i40evf
Search vendor "Linux" for product "Linux Kernel I40e\/i40evf"
--
Affected
Dpdk
Search vendor "Dpdk"
Dpdk
Search vendor "Dpdk" for product "Dpdk"
--
Affected