CVE-2023-45236: Predictable TCP ISNs in EDK II Network Package
EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.
Other sources
https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html https://github.com/advisories/GHSA-fqc4-ffq5-4r98
— Red Hat
Predictable TCP ISNs in EDK II Network Package
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45236?
CVE-2023-45236 has a high severity rating due to its potential to allow unauthorized access.
How does CVE-2023-45236 exploit predictability in TCP Initial Sequence Numbers?
CVE-2023-45236 exploits predictable TCP Initial Sequence Numbers to enable attackers to hijack network sessions.
What versions of EDK2 are affected by CVE-2023-45236?
CVE-2023-45236 affects EDK2 versions up to and including 202311.
How do I mitigate CVE-2023-45236?
Mitigation for CVE-2023-45236 involves updating EDK2 to the latest version that addresses the vulnerability.
What impact can CVE-2023-45236 have on confidentiality?
CVE-2023-45236 can lead to a loss of confidentiality, allowing attackers to intercept sensitive data.