CVE-2023-45232 is an infinite loop vulnerability in EDK2's Network Package, specifically affecting tianocore edk2 products when parsing unknown IPv6 Destination Options. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-exploitable, low-complexity attack that can lead to a complete loss of availability. While not currently listed on the KEV catalog or Hot List, and lacking public exploit code, it has garnered significant community discussion and media coverage, suggesting potential future interest from attackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 202311CPE matchmatch criteria | cpe:2.3:a:tianocore:edk2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP PC BIOS Security Update for EDK2 NetworkPkg
Oct 24, 2024CVE-2023-45232
Sep 10, 2024edk2: Infinite loop when parsing unknown options in the Destination Options header
Jan 16, 2024Infinite loop in EDK II Network Package
Jan 9, 2024