PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-45235 TianoCore CVE debrief

CVE-2023-45235 is a high-severity buffer overflow vulnerability in EDK2's Network Package. An attacker can exploit this vulnerability to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity, and/or Availability. The vulnerability occurs when handling Server ID option from a DHCPv6 proxy Advertise message. This CVE was published on January 29, 2026, and modified on May 21, 2026. The CVSS score is 8.3, indicating high severity.

Vendor
TianoCore
Product
APC4100
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-29
Original CVE updated
2026-05-21
Advisory published
2026-01-29
Advisory updated
2026-05-21

Who should care

Organizations using ABB's APC4100 and other affected products should prioritize patching this vulnerability. The vulnerability's high severity and potential impact on Confidentiality, Integrity, and Availability make it critical for defenders to take immediate action. Security teams should review their inventory and apply patches or mitigations as recommended by the vendor.

Technical summary

The EDK2 Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability, tracked as CVE-2023-45235, can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity, and/or Availability. The vulnerability has a CVSS score of 8.3, indicating high severity. ABB has released patches for affected products, and defenders should apply them as soon as possible.

Defensive priority

High priority should be given to patching CVE-2023-45235, as it has a high CVSS score and can lead to significant impacts on Confidentiality, Integrity, and Availability. Defenders should review their inventory, apply patches or mitigations, and monitor for potential exploitation attempts.

Recommended defensive actions

  • Apply patches or updates provided by the vendor for affected products.
  • Deactivate the vulnerable component if not needed.
  • Limit accessibility to legitimate users and block illegitimate PXE traffic.
  • Review and update network traffic rules to prevent exploitation.
  • Monitor for potential exploitation attempts and implement compensating controls if necessary.

Evidence notes

The CVE-2023-45235 vulnerability is documented in multiple sources, including CVE.org, NVD, and CISA's CSAF files. The vulnerability affects several ABB products, including APC4100, APC910, C80, MPC3100, PPC1200, PPC900, APC2200, PPC2200, APC3100, and PPC3100. ABB has provided patches and mitigations for affected products.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-45235 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-45235

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-45235 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-45235

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-141-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://psirt.abb.com/csaf/2026/sa24p003.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.br-automation.com/fileadmin/SA24P003-bb9ea116.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.