Unrated severityNVD Advisory· Published Jan 16, 2024· Updated Nov 4, 2025
Use of a Weak PseudoRandom Number Generator in EDK II Network Package
CVE-2023-45237
Description
EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.
Affected products
1- TianoCore/edk2v5Range: edk2-stable202308
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
1- ABB B&R PCsCISA ICS Advisories