CVE-2024-38797 - CERT CVE
ID CVE-2024-38797
Sažetak EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.
Reference
CVSS
Base: 4.6
Impact: 2.5
Exploitability:2.1
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
NONE LOW LOW
CVSS vektor CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Zadnje važnije ažuriranje 07-04-2025 - 18:15
Objavljeno 07-04-2025 - 18:15