cbcvebase.
CVE-2023-45234
published 2024-01-16

CVE-2023-45234: EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability…

high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianedk2< edk2 2022.11-6+deb12u1 (bookworm)edk2 2022.11-6+deb12u1 (bookworm)
msrcazl3_edk2_20230301gitf80f052277c8-37_on_azure_linux_3.0
msrcazl3_edk2_20240223gitedc6681206c1-1_on_azure_linux_3.0
msrcazl3_qemu_8.2.0-16_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_edk2_20230301gitf80f052277c8-40_on_cbl_mariner_2.0
msrccbl2_edk2_20230301gitf80f052277c8-41_on_cbl_mariner_2.0
msrccbl2_hvloader_1.0.1-11_on_cbl_mariner_2.0
msrccbl2_hvloader_1.0.1-9_on_cbl_mariner_2.0
msrccbl2_qemu_6.2.0-24_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
paloaltopan-os
paloaltoprisma_access
tianocoreedk2<= 202311
tianocoreedk2
tianocoreedk2>= 0 < 2020.11-2+deb11u32020.11-2+deb11u3
tianocoreedk2>= 0 < 2022.11-6+deb12u12022.11-6+deb12u1
tianocoreedk2>= 0 < 2023.11-62023.11-6
tianocoreedk2>= 0 < 2023.11-62023.11-6
tianocoreedk2>= 0 < 0~20191122.bd85bf54-2ubuntu3.50~20191122.bd85bf54-2ubuntu3.5
tianocoreedk2>= 0 < 2022.02-3ubuntu0.22.04.22022.02-3ubuntu0.22.04.2

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH