CVE-2023-45235 - CERT CVE
ID CVE-2023-45235
Sažetak EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.
Reference
CVSS
Base: 8.3
Impact: 5.5
Exploitability:2.8
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH LOW HIGH
CVSS vektor CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Zadnje važnije ažuriranje 13-02-2025 - 18:15
Objavljeno 16-01-2024 - 16:15