CVE-2023-45235
published 2024-01-16CVE-2023-45235: EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This…
high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EDK2's Network Package is susceptible to a buffer overflow vulnerability when
handling Server ID option
from a DHCPv6 proxy Advertise message. This
vulnerability can be exploited by an attacker to gain unauthorized
access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | edk2 | < edk2 2022.11-6+deb12u1 (bookworm) | edk2 2022.11-6+deb12u1 (bookworm) |
| msrc | azl3_edk2_20230301gitf80f052277c8-37_on_azure_linux_3.0 | — | — |
| msrc | azl3_edk2_20240223gitedc6681206c1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-16_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_edk2_20230301gitf80f052277c8-40_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_edk2_20230301gitf80f052277c8-41_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_hvloader_1.0.1-11_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_hvloader_1.0.1-9_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_qemu_6.2.0-24_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| paloalto | pan-os | — | — |
| paloalto | prisma_access | — | — |
| tianocore | edk2 | <= 202311 | — |
| tianocore | edk2 | — | — |
| tianocore | edk2 | >= 0 < 2020.11-2+deb11u3 | 2020.11-2+deb11u3 |
| tianocore | edk2 | >= 0 < 2022.11-6+deb12u1 | 2022.11-6+deb12u1 |
| tianocore | edk2 | >= 0 < 2023.11-6 | 2023.11-6 |
| tianocore | edk2 | >= 0 < 2023.11-6 | 2023.11-6 |
| tianocore | edk2 | >= 0 < 0~20191122.bd85bf54-2ubuntu3.5 | 0~20191122.bd85bf54-2ubuntu3.5 |
| tianocore | edk2 | >= 0 < 2022.02-3ubuntu0.22.04.2 | 2022.02-3ubuntu0.22.04.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH