Unrated severityNVD Advisory· Published Jan 16, 2024· Updated Nov 4, 2025
Out-of-Bounds Read in EDK II Network Package
CVE-2023-45229
Description
EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.
Affected products
1- TianoCore/edk2v5Range: edk2-stable202308
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
1- ABB B&R PCsCISA ICS Advisories