CVE-2023-45232 PUBLISHED CVSS 7.5 HIGH

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

EPSS 0.48% · 65.0th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
EPSS Score
0.48%
65.0th percentile

Affected Products

VendorProductVersions
ABBABB PPC2200 <1.35
ABBABB APC4100 <1.09
ABBABB MPC3100 <1.24
ABBABB APC3100 <1.45
ABBABB PPC1200 <1.14
ABBABB APC2200 <1.35
ABBABB PPC3100 <1.45
ABBABB PPC900 <2.16
ABBABB C80 <1.14
ABBABB APC910 <=1.25

Timeline

References

Open in Interactive Console →