Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-45231

Опубликовано: 16 янв. 2024
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing  Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

A security loophole involving an out-of-bounds read was identified in EDK2, the open-source reference implementation of the UEFI specification. This vulnerability enables an unauthorized attacker within the vicinity of the network to transmit a specifically crafted Neighbor Discovery Redirect message. Consequently, this may lead to the unauthorized reading of memory beyond the message boundaries, potentially resulting in the exposure of sensitive information.

Отчет

The out-of-bounds read vulnerability in EDK2 represents a moderate security concern. This flaw, found in the open-source implementation of the UEFI specification, allows an attacker within the local network to exploit the issue by sending a carefully crafted Neighbor Discovery Redirect message. While requiring proximity for exploitation, the vulnerability could lead to unauthorized memory access and potential leakage of sensitive information.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2258688edk2: Out of Bounds read when handling a ND Redirect message with truncated options

EPSS

Процентиль: 29%
0.00102
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

CVSS3: 6.5
nvd
больше 1 года назад

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing  Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

CVSS3: 6.5
msrc
около 1 года назад

Описание отсутствует

CVSS3: 6.5
debian
больше 1 года назад

EDK2's Network Package is susceptible to an out-of-bounds read vulner ...

CVSS3: 6.5
github
больше 1 года назад

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing  Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

EPSS

Процентиль: 29%
0.00102
Низкий

6.5 Medium

CVSS3