Security Advisory

CVE-2023-45235

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-01-16 16:11:41
Last updated 2025-11-04 18:17:39
Assigner TianoCore
CVSS score 8.3
State PUBLISHED

Description

EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.