Fiche vulnérabilité
CVE-2023-45232 : faille élevée tianocore edk2 (CVSS 7.5)
Description
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 16 janv. 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- tianocore edk2
Références
- Fiche CVE-2023-45232 sur le NVD (NIST)
- packetstormsecurity.com/files/176574/PixieFail-Proof-Of-Concepts.html
- openwall.com/lists/oss-security/2024/01/16/2
- github.com/tianocore/edk2/security/advisories/GHSA…
- lists.fedoraproject.org/archives/list/package…
- security.netapp.com/advisory/ntap-20240307-0011/
- lists.debian.org/debian-lts-announce/2025/06/msg00007.html
- kb.cert.org/vuls/id/132380