Description
EDK2's Network Package is susceptible to an out-of-bounds read
vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This
vulnerability can be exploited by an attacker to gain unauthorized
access and potentially lead to a loss of Confidentiality.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6Attack Vector: Adjacent
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
2CVEListOut-of-Bounds Read in EDK II Network Package↗2024-01-16 ▶ OSVCVE-2023-45229: EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message↗2024-01-16 ▶ 📋Vendor Advisories
3Red Hatedk2: Integer underflow when processing IA_NA/IA_TA options in a DHCPv6 Advertise message↗2024-01-16 ▶ MicrosoftOut-of-Bounds Read in EDK II Network Package↗2024-01-09 ▶ DebianCVE-2023-45229: edk2 - EDK2's Network Package is susceptible to an out-of-bounds read vulnerability wh...↗2023 ▶