{"id":112965,"date":"2024-01-17T23:28:01","date_gmt":"2024-01-17T21:28:01","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/pixiefail-uyazvimosti-v-setevom-steke-proshivok-uefi-primenyaemom-dlya-pxe-zagruzki"},"modified":"2024-01-17T23:28:01","modified_gmt":"2024-01-17T21:28:01","slug":"pixiefail-uyazvimosti-v-setevom-steke-proshivok-uefi-primenyaemom-dlya-pxe-zagruzki","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/pixiefail-uyazvimosti-v-setevom-steke-proshivok-uefi-primenyaemom-dlya-pxe-zagruzki","title":{"rendered":"PixieFAIL \u2014 vulnerabilities in the UEFI firmware network stack used for PXE booting","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nine vulnerabilities, collectively codenamed PixieFAIL, have been identified in UEFI firmware based on the open source platform TianoCore EDK2, commonly used in server systems. These vulnerabilities exist in the firmware's network stack, which is used for network booting (PXE). The most critical vulnerabilities allow an unauthenticated attacker to execute their code remotely at the firmware level on systems that permit PXE booting using IPv6.     <\/p>\n<p>Less severe issues lead to denial of service (boot blocking), information leakage, DNS cache poisoning, and interception of TCP sessions. Most vulnerabilities can be exploited from the local network, but some allow attacks from the external network as well. A typical attack scenario involves monitoring traffic on the local network and sending specially crafted packets upon detecting activity related to PXE system boot. Access to <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-shicago\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2874\">server<\/a> the boot process or DHCP server is not required. Prototypes of exploits have been published to demonstrate the attack technique.       <\/p>\n<p>UEFI firmware based on the TianoCore EDK2 platform is used by many large companies, cloud providers, data centers, and computing clusters. In particular, the vulnerable NetworkPkg module implementing PXE booting is used in firmware developed by companies such as ARM, Insyde Software (Insyde H20 UEFI BIOS), American Megatrends (AMI Aptio OpenEdition), Phoenix Technologies (SecureCore), Intel, Dell, and Microsoft (Project Mu). It was thought that the vulnerabilities also affect the ChromeOS platform, which has a package of EDK2 in its repository, but Google stated that this package is not used in the firmware for Chromebook devices and that the ChromeOS platform is not susceptible to the issue.        <\/p>\n<p>Identified vulnerabilities:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2023-45230 \u2014 Buffer overflow in the DHCPv6 client code, exploited through the transmission of an excessively long identifier. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-los-angeles\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3612\">server<\/a> (Server ID option).\n<li class=\"l\"> CVE-2023-45234 \u2014 Buffer overflow when processing DNS server parameters in options transmitted in messages announcing the presence of a DHCPv6 server.\n<li class=\"l\"> CVE-2023-45235 \u2014 Buffer overflow when processing the Server ID option in proxy server announcement messages for DHCPv6.\n<li class=\"l\"> CVE-2023-45229 \u2014 Integer underflow occurring when processing IA_NA\/IA_TA options in DHCPv6 messages announcing a DHCP server.\n<li class=\"l\"> CVE-2023-45231 \u2014 Data leakage from outside the buffer when processing ND Redirect (Neighbor Discovery) messages with truncated option values.\n<li class=\"l\"> CVE-2023-45232 \u2014 Infinite loop when parsing unknown options in the Destination Options header.\n<li class=\"l\"> CVE-2023-45233 \u2014 Infinite loop when parsing the PadN option in the packet header.\n<li class=\"l\"> CVE-2023-45236 \u2014 Use of predictable initial TCP sequence numbers, allowing injection into a TCP connection.\n<li class=\"l\"> CVE-2023-45237 \u2014 Use of an unreliable pseudorandom number generator that produces predictable values.  <\/ul>\n<p>Information about the vulnerabilities was submitted to CERT\/CC on August 3, 2023, with disclosure originally scheduled for November 2. However, due to the need for a coordinated release of patches covering multiple vendors, the publication date was initially pushed to December 1, then postponed to December 12 and December 19, 2023, but ultimately disclosed on January 16, 2024. Microsoft requested to delay public disclosure until May.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60449\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b TianoCore EDK2, \u043e\u0431\u044b\u0447\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0445 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 9 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0438\u0445 \u0441\u043e\u0431\u0438\u0440\u0430\u0442\u0435\u043b\u044c\u043d\u043e\u0435 \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f PixieFAIL. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u044e\u0442 \u0432 \u0441\u0435\u0442\u0435\u0432\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u043f\u0440\u043e\u0448\u0438\u0432\u043e\u043a, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 (PXE). \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u043d\u0435\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0438\u0445 PXE-\u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0443 \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u0441\u0435\u0442\u0438 IPv6. [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-112965","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b TianoCore EDK2, \u043e\u0431\u044b\u0447\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0445 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 9 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0438\u0445 \u0441\u043e\u0431\u0438\u0440\u0430\u0442\u0435\u043b\u044c\u043d\u043e\u0435 \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f PixieFAIL.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/pixiefail-uyazvimosti-v-setevom-steke-proshivok-uefi-primenyaemom-dlya-pxe-zagruzki\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47PixieFAIL \u2014 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0441\u0435\u0442\u0435\u0432\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u043f\u0440\u043e\u0448\u0438\u0432\u043e\u043a UEFI, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0434\u043b\u044f PXE-\u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b TianoCore EDK2, \u043e\u0431\u044b\u0447\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0445 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 9 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0438\u0445 \u0441\u043e\u0431\u0438\u0440\u0430\u0442\u0435\u043b\u044c\u043d\u043e\u0435 \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f PixieFAIL.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/pixiefail-uyazvimosti-v-setevom-steke-proshivok-uefi-primenyaemom-dlya-pxe-zagruzki\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-01-17T21:28:01+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-01-17T21:28:01+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47PixieFAIL \u2014 vulnerabilities in the UEFI firmware network stack used for PXE booting | ProHoster","description":"Nine vulnerabilities, collectively dubbed PixieFAIL, were identified in UEFI firmware based on the open TianoCore EDK2 platform, commonly used in server systems.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/pixiefail-uyazvimosti-v-setevom-steke-proshivok-uefi-primenyaemom-dlya-pxe-zagruzki","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47PixieFAIL \u2014 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0441\u0435\u0442\u0435\u0432\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u043f\u0440\u043e\u0448\u0438\u0432\u043e\u043a UEFI, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0434\u043b\u044f PXE-\u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 | ProHoster","og:description":"\u0412 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b TianoCore EDK2, \u043e\u0431\u044b\u0447\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0445 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 9 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0438\u0445 \u0441\u043e\u0431\u0438\u0440\u0430\u0442\u0435\u043b\u044c\u043d\u043e\u0435 \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f PixieFAIL.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/pixiefail-uyazvimosti-v-setevom-steke-proshivok-uefi-primenyaemom-dlya-pxe-zagruzki","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-01-17T21:28:01+00:00","article:modified_time":"2024-01-17T21:28:01+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"112965","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-09 21:41:52","updated":"2026-02-22 15:29:22","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/112965","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=112965"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/112965\/revisions"}],"predecessor-version":[{"id":162139,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/112965\/revisions\/162139"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=112965"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=112965"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=112965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}