IM
IronMonkey Threat Research

CVE-2023-45232 HIGH

Published: 2024-01-16 | Last Modified: 2025-11-04 | Status: Modified

Description

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

Additional Descriptions (1)

EDK2's Network Package es susceptible a una vulnerabilidad de bucle infinito al analizar opciones desconocidas en el encabezado Destination Options de IPv6. Un atacante puede aprovechar esta vulnerabilidad para obtener acceso no autorizado y potencialmente provocar una pérdida de disponibilidad.

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-835
[email protected] Primary
en CWE-835

Affected Products

Vendor Product Version Update Type
tianocore edk2 * <built-in method update of dict object at 0x7b06e87f2f80> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:tianocore:edk2:*:*:*:*:*:*:*:*
Notification
Message here