CVE-2023-45230

HIGH

EDK2 < 202311 - Buffer Overflow via DHCPv6 Server ID Option

Title source: llm
STIX 2.1

Description

EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.

Scores

CVSS v3 8.3
EPSS 0.0121
EPSS Percentile 64.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119
Status published
Products (1)
tianocore/edk2 < 202311
Published Jan 16, 2024
Tracked Since Feb 18, 2026