VDB

CVE-2023-45232

CVE-2023-45232 PUBLISHED CVSS 7.5 HIGH

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

EPSS 2.10% · 81.0th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
EPSS Score
2.10%
81.0th percentile

Affected Products

VendorProductVersions
ABBABB PPC2200 <1.35
ABBABB APC4100 <1.09
ABBB&R Industrial Automation GmbH PPC2200 <1.35
ABBABB MPC3100 <1.24
ABBABB APC3100 <1.45
ABBB&R Industrial Automation GmbH PPC900 <2.16
ABBB&R Industrial Automation GmbH APC910 <=1.25
ABBB&R Industrial Automation GmbH APC2200 <1.35
ABBB&R Industrial Automation GmbH PPC1200 <1.14
ABBABB PPC1200 <1.14
ABBB&R Industrial Automation GmbH PPC3100 <1.45
ABBB&R Industrial Automation GmbH C80 <1.14
ABBABB APC2200 <1.35
ABBABB PPC3100 <1.45
ABBB&R Industrial Automation GmbH APC4100 <1.09
ABBABB PPC900 <2.16
ABBB&R Industrial Automation GmbH APC3100 <1.45
ABBABB C80 <1.14
ABBABB APC910 <=1.25
ABBB&R Industrial Automation GmbH MPC3100 <1.24

Timeline

  • Jan 16, 2024 CVE Published
  • Jan 24, 2024 EPSS Score
  • Feb 21, 2024 EPSS Score
  • Mar 8, 2024 EPSS Score
  • Apr 18, 2024 EPSS Score
  • May 16, 2024 EPSS Score
  • Jun 13, 2024 EPSS Score
  • Jul 11, 2024 EPSS Score
  • Sep 6, 2024 EPSS Score
  • Oct 4, 2024 EPSS Score
  • Nov 1, 2024 EPSS Score
  • Nov 30, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›