VDB
CVE-2023-45232
CVE-2023-45232
PUBLISHED
CVSS 7.5 HIGH
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.
EPSS 0.46% · 64.6th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
EPSS Score
0.46%
64.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ABB | ABB PPC2200 <1.35 | |
| ABB | ABB APC4100 <1.09 | |
| ABB | B&R Industrial Automation GmbH PPC2200 <1.35 | |
| ABB | ABB MPC3100 <1.24 | |
| ABB | ABB APC3100 <1.45 | |
| ABB | B&R Industrial Automation GmbH PPC900 <2.16 | |
| ABB | B&R Industrial Automation GmbH APC910 <=1.25 | |
| ABB | B&R Industrial Automation GmbH APC2200 <1.35 | |
| ABB | B&R Industrial Automation GmbH PPC1200 <1.14 | |
| ABB | ABB PPC1200 <1.14 | |
| ABB | B&R Industrial Automation GmbH PPC3100 <1.45 | |
| ABB | B&R Industrial Automation GmbH C80 <1.14 | |
| ABB | ABB APC2200 <1.35 | |
| ABB | ABB PPC3100 <1.45 | |
| ABB | B&R Industrial Automation GmbH APC4100 <1.09 | |
| ABB | ABB PPC900 <2.16 | |
| ABB | B&R Industrial Automation GmbH APC3100 <1.45 | |
| ABB | ABB C80 <1.14 | |
| ABB | ABB APC910 <=1.25 | |
| ABB | B&R Industrial Automation GmbH MPC3100 <1.24 |
Exploit Intelligence
- https://lists.debian.org/debian-lts-announce/2025/06/msg00007.html (circl)
- https://www.kb.cert.org/vuls/id/132380 (circl)
- https://github.com/tianocore/edk2/security/advisories/GHSA-hc6x-cw6p-gj7h (circl)
- http://www.openwall.com/lists/oss-security/2024/01/16/2 (circl)
- http://packetstormsecurity.com/files/176574/PixieFail-Proof-Of-Concepts.html (circl)
- https://security.netapp.com/advisory/ntap-20240307-0011/ (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SJ42V7O7F4OU6R7QSQQECLB6LDHKZIMQ/ (circl)
Timeline
- Jan 16, 2024 CVE Published
- Jan 24, 2024 EPSS Score
- Feb 21, 2024 EPSS Score
- Mar 8, 2024 EPSS Score
- Apr 16, 2024 EPSS Score
- May 14, 2024 EPSS Score
- Jun 11, 2024 EPSS Score
- Jul 9, 2024 EPSS Score
- Aug 6, 2024 EPSS Score
- Sep 30, 2024 EPSS Score
- Oct 28, 2024 EPSS Score
- Nov 25, 2024 EPSS Score