CVE-2023-45236

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
16/01/2024
Last modified:
04/11/2025

Description

EDK2&amp;#39;s Network Package is susceptible to a predictable TCP Initial Sequence Number. This<br /> vulnerability can be exploited by an attacker to gain unauthorized <br /> access and potentially lead to a loss of Confidentiality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tianocore:edk2:*:*:*:*:*:*:*:* 202311 (including)