CVE detail
CVE-2023-52080 — CVE-2023-52080
Published 2024-04-29 · Modified 2026-06-17 · Source nvd
HIGH
severity
CVSS-derived band
0.0020
EPSS probability
exploitation probability, 30d
10.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
IEIT NF5280M6 UEFI firmware through 8.4 has a pool overflow vulnerability, caused by improper use of the gRT->GetVariable() function. Attackers with access to local NVRAM variables can exploit this by modifying these variables on SPI Flash, resulting in memory data being tampered with. When critical data in memory data is tampered with,a crash may occur.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References