PT-2021-4745 · Tianocore+8 · Tianocore Edk2+8

Published

2014-10-06

·

Updated

2025-06-05

·

CVE-2021-38575

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetworkPkg/IScsiDxe (affected versions not specified) Tianocore edk2 (affected versions not specified)
Description The issue is related to remotely exploitable buffer overflows in the NetworkPkg/IScsiDxe and the IScsiHexToBin function of the Tianocore edk2 library. This can allow a remote attacker to disclose protected information, impact data integrity, or cause a denial of service.
Recommendations For NetworkPkg/IScsiDxe, consider disabling the vulnerable component until a patch is available. For Tianocore edk2, restrict access to the IScsiHexToBin function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2246
BDU:2021-05454
CESA-2021_3066
CVE-2021-38575
DLA-4207-1
OESA-2021-1358
RHSA-2021:3066
RHSA-2021:3172
RHSA-2021:3235
RHSA-2021:3369
RHSA-2021_3066
RLSA-2021:3066
USN-5088-1
USN-7060-1

Affected Products

Alt Linux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Rocky Linux
Tianocore Edk2
Ubuntu