CVE-2023-45229 is an out-of-bounds read vulnerability in EDK2's Network Package, specifically affecting Tianocore EDK II when processing DHCPv6 Advertise messages containing IA_NA or IA_TA options. This medium-severity vulnerability (CVSS 6.5) allows an adjacent attacker to achieve unauthorized access and potentially compromise confidentiality with low attack complexity and no user interaction. While there is no known public exploit code or active exploitation (KEV: No), the vulnerability has garnered significant community attention and media coverage, indicating its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 202311CPE matchmatch criteria | cpe:2.3:a:tianocore:edk2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP PC BIOS Security Update for EDK2 NetworkPkg
Oct 24, 2024CVE-2023-45229
Jun 11, 2024edk2: Integer underflow when processing IA_NA/IA_TA options in a DHCPv6 Advertise message
Jan 16, 2024Out-of-Bounds Read in EDK II Network Package
Jan 9, 2024