VDB

CVE-2023-45232

CVE-2023-45232 PUBLISHED CVSS 7.5 HIGH

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

EPSS 0.46% · 64.6th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
EPSS Score
0.46%
64.6th percentile

Affected Products

VendorProductVersions
ABBABB PPC2200 <1.35
ABBABB APC4100 <1.09
ABBB&R Industrial Automation GmbH PPC2200 <1.35
ABBABB MPC3100 <1.24
ABBABB APC3100 <1.45
ABBB&R Industrial Automation GmbH PPC900 <2.16
ABBB&R Industrial Automation GmbH APC910 <=1.25
ABBB&R Industrial Automation GmbH APC2200 <1.35
ABBB&R Industrial Automation GmbH PPC1200 <1.14
ABBABB PPC1200 <1.14
ABBB&R Industrial Automation GmbH PPC3100 <1.45
ABBB&R Industrial Automation GmbH C80 <1.14
ABBABB APC2200 <1.35
ABBABB PPC3100 <1.45
ABBB&R Industrial Automation GmbH APC4100 <1.09
ABBABB PPC900 <2.16
ABBB&R Industrial Automation GmbH APC3100 <1.45
ABBABB C80 <1.14
ABBABB APC910 <=1.25
ABBB&R Industrial Automation GmbH MPC3100 <1.24

Timeline

  • Jan 16, 2024 CVE Published
  • Jan 24, 2024 EPSS Score
  • Feb 21, 2024 EPSS Score
  • Mar 8, 2024 EPSS Score
  • Apr 16, 2024 EPSS Score
  • May 14, 2024 EPSS Score
  • Jun 11, 2024 EPSS Score
  • Jul 9, 2024 EPSS Score
  • Aug 6, 2024 EPSS Score
  • Sep 30, 2024 EPSS Score
  • Oct 28, 2024 EPSS Score
  • Nov 25, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›