Related Vulnerabilities: CVE-2021-38575  

In EDK II before version 202108, a remotely exploitable buffer overflow has been found in the IScsiHexToBin() function.

Severity Medium

Remote Yes

Type Arbitrary code execution

Description

In EDK II before version 202108, a remotely exploitable buffer overflow has been found in the IScsiHexToBin() function.

AVG-2382 edk2-shell 202105-1 202108-1 Medium Fixed

https://bugzilla.tianocore.org/show_bug.cgi?id=3356
https://github.com/tianocore/edk2/pull/1698