cbcvebase.
CVE-2023-45231
published 2024-01-16

CVE-2023-45231: EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be…

medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianedk2< edk2 2022.11-6+deb12u1 (bookworm)edk2 2022.11-6+deb12u1 (bookworm)
msrcazl3_edk2_20230301gitf80f052277c8-37_on_azure_linux_3.0
msrcazl3_edk2_20240223gitedc6681206c1-1_on_azure_linux_3.0
msrcazl3_qemu_8.2.0-16_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_edk2_20230301gitf80f052277c8-42_on_cbl_mariner_2.0
msrccbl2_hvloader_1.0.1-11_on_cbl_mariner_2.0
msrccbl2_hvloader_1.0.1-9_on_cbl_mariner_2.0
msrccbl2_qemu_6.2.0-24_on_cbl_mariner_2.0
msrccbl2_qemu_6.2.0-25_on_cbl_mariner_2.0
msrccbl2_qemu_6.2.0-26_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
paloaltopan-os
paloaltoprisma_access
tianocoreedk2<= 202311
tianocoreedk2
tianocoreedk2>= 0 < 2020.11-2+deb11u32020.11-2+deb11u3
tianocoreedk2>= 0 < 2022.11-6+deb12u12022.11-6+deb12u1
tianocoreedk2>= 0 < 2023.11-62023.11-6
tianocoreedk2>= 0 < 2023.11-62023.11-6
tianocoreedk2>= 0 < 0~20191122.bd85bf54-2ubuntu3.50~20191122.bd85bf54-2ubuntu3.5
tianocoreedk2>= 0 < 2022.02-3ubuntu0.22.04.22022.02-3ubuntu0.22.04.2

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.8HIGH