Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities BSI Germany

[UPDATE] [hoch] EDK2 NetworkPkg IP stack implementation: Mehrere Schwachstellen

Multiple high-severity vulnerabilities (CVSS Base Score 8.3) in the EDK2 NetworkPkg IP stack implementation allow a remote attacker from an adjacent network to execute arbitrary code, disclose information, or cause a denial of service. The vulnerabilities affect a wide range of UEFI BIOS/firmware and operating systems, including specific Insyde UEFI Firmware kernels below versions 05.28.49, 05.37.49, 05.45.49, 05.53.49, and 05.60.49, as well as numerous listed vendor platforms. A mitigation is available, and affected organizations should apply the relevant vendor-specific firmware or OS updates.
Read Full Article →

[WID-SEC-2024-0126] EDK2 NetworkPkg IP stack implementation: Mehrere Schwachstellen CVSS Base Score 8.3 (hoch) CVSS Temporal Score 7.2 (hoch) Remoteangriff ja Datum 16.01.2024 Stand UPDATE 10.07.2026 Mitigation ja Betroffene Systeme Betriebssystem BIOS/Firmware Produktbeschreibung InsydeH2O UEFI BIOS ist eine proprietäre, lizenzierte UEFI-BIOS-Firmware, die Intel und AMD basierte Computer unterstützt. Produkte UPDATE 04.12.2025 HP Computer Cray XD670 <v2.06 UPDATE 11.02.2025 Lenovo Computer Lenovo BIOS UPDATE 10.02.2025 SUSE Linux UPDATE 10.11.2024 HPE ProLiant UPDATE 24.10.2024 HP Computer UPDATE 17.04.2024 Dell Computer Dell BIOS UPDATE 03.04.2024 HPE Synergy HPE ProLiant UPDATE 12.03.2024 RESF Rocky Linux UPDATE 06.03.2024 Oracle Linux UPDATE 04.03.2024 Amazon Linux 2 UPDATE 26.02.2024 Red Hat Enterprise Linux Fedora Linux UPDATE 20.02.2024 Dell PowerEdge T30 <1.14.0 Dell PowerEdge T40 <1.15.0 UPDATE 14.02.2024 Debian Linux Ubuntu Linux Lenovo Computer UPDATE 30.01.2024 Dell BIOS 16.01.2024 Insyde UEFI Firmware Kernel <05.28.49 Insyde UEFI Firmware Kernel <05.37.49 Insyde UEFI Firmware Kernel <05.45.49 Insyde UEFI Firmware Kernel <05.53.49 Insyde UEFI Firmware Kernel <05.60.49 Angriff Angriff Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in der EDK2 NetworkPkg IP stack implementation ausnutzen, um beliebigen Programmcode auszuführen, vertrauliche Informationen offenzulegen und einen Denial of Service Zustand auszulösen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Share this article