CVE-2023-45229: Tianocore EDK2

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

Affected products

Published 2024-01-16. Last modified 2026-06-17.