Vulnerabilities
Vulnerable Software
Tianocore:  Security Vulnerabilities
EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.
CVSS Score
8.3
EPSS Score
0.002
Published
2024-01-16
EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing  Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-01-16
EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
CVSS Score
7.0
EPSS Score
0.001
Published
2024-01-09
EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
CVSS Score
7.0
EPSS Score
0.0
Published
2024-01-09
EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
CVSS Score
7.0
EPSS Score
0.0
Published
2024-01-09
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
CVSS Score
7.4
EPSS Score
0.001
Published
2022-03-03
A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-01-03
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
CVSS Score
8.1
EPSS Score
0.006
Published
2021-12-01
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
CVSS Score
7.8
EPSS Score
0.001
Published
2021-08-05
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
CVSS Score
6.8
EPSS Score
0.001
Published
2021-07-14


Contact Us

Shodan ® - All rights reserved