All pages
Powered by GitBook
1 of 13

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Security Advisories

2024 - October

Advisory ID
Impact
Title
Type
Severity
Published
Last Updated

Advisory ID
Impact
Title
Type
Severity
Published
Last Updated
Advisory ID
Impact
Title
Type
Severity
Published
Last Updated

OL 2025 080402

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2025-080402

Type: Advisory

Fixed Vulnerabilities:

Critical

03/11/2025

03/11/2025

Helix 400 series

Mitigation for Helix 400 series

Advisory

Critical

03/11/2025

03/11/2025

CL250

Mitigation for CL250

Advisory

Medium

03/11/2025

03/11/2025

ML350

Mititgation for ML350

Advisory

Medium

03/11/2025

03/11/2025

Critical

06/13/2025

06/13/2025

KARBON 800 series

Mitigation for KARBON 800 series

Advisory

Critical

10/13/2024

10/13/2024

OL-2024-080101

Helix 400 series

Mitigation for Helix 400 series

Advisory

Critical

10/13/2024

10/13/2024

OL-2024-090101

CL250

Mitigation for CL250

Advisory

Medium

10/13/2024

02/03/2025

OL-2024-090102

ML350

Mitigation for ML350

Advisory

Medium

10/15/2024

02/03/2024

OL-2024-090401

KARBON 300

Mitigation for KARBON 300

Advisory

High

10/15/2024

10/15/2024

OL-2024-0B0001

AC101

Mitigation for AC101

Advisory

High

10/15/2024

10/15/2024

OL-2024-0B0002

MK100B-40

Mitigation for MK100B-40

Advisory

High

10/15/2024

02/03/2024

OL-2025-080402

KARBON 800 series

Mitigation for KARBON 800 series

OL-2025-0A0101

AXIAL AX30X series

Mitigation for AXIAL AX30X series

2025 - March

2025 - June

OL-2024-080401
Subscribe to security updates

Advisory

Advisory

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2023-40238

OOB Write in RLE4 decode routine during BMP file processing in Insyde firmware.

5.5

CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

V2.05

V2.15

CVE-2021-41842,CVE-2024-27353 CVE-2024-25079,CVE-2024-25078 CVE-2022-36448,CVE-2022-35895 CVE-2022-35893,CVE-2022-35408 CVE-2022-34325,CVE-2022-24069 CVE-2022-24031,CVE-2022-24030 CVE-2021-45971,CVE-2021-45970 CVE-2021-45969,CVE-2021-43323 CVE-2021-42554,CVE-2021-41841 CVE-2021-41839,CVE-2021-41838 CVE-2021-41837,CVE-2021-33625, CVE-2022-46897,CVE-2022-35894

Fix issues discovered in InsydeH2O

7.5 ~ 8.2

CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

V2.05

V2.15

CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234

Fix ipv6 issues discovered in EDK2

7.5 ~ 8.3

CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

V2.05

V2.15

BRLY-2023-002

Found and fix unsafe code flow.

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

V2.05

V2.15

First Public Date: 2025/03/11

Last Update Date: 2025/03/11

Affected Products:

  • Karbon 800 Series by OnLogic

Update BIOS version to V2.15

Vulnerability

OL-2025-080102
OL-2025-090102
OL-2025-090103
Subscribe to security updates

OL 2025 090102

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2025-090102

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2025/03/11

Last Update Date: 2025/03/11

Affected Products:

Update BIOS version to N7870A01

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2014-3686

Found and fixed unsafe code flow

6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

D7870A13

N7870A01

CVE-2015-0210

Found and fixed unsafe code flow

5.9

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

D7870A13

N7870A01

CVE-2015-1863

Found and fixed unsafe code flow

5.8

AV:A/AC:L/Au:N/C:P/I:P/A:P

D7870A13

N7870A01

CVE-2015-4141

Found and fixed unsafe code flow

4.3

AV:N/AC:M/Au:N/C:N/I:N/A:P

D7870A13

N7870A01

CVE-2015-4142

Found and fixed unsafe code flow

4.3

V:N/AC:M/Au:N/C:N/I:N/A:P

D7870A13

N7870A01

CVE-2015-4143

Found and fixed unsafe code flow

5

AV:N/AC:L/Au:N/C:N/I:N/A:P

D7870A13

N7870A01

CVE-2015-4144

Found and fixed unsafe code flow

5

AV:N/AC:L/Au:N/C:N/I:N/A:P

D7870A13

N7870A01

CVE-2015-4145

Found and fixed unsafe code flow

5

AV:N/AC:L/Au:N/C:N/I:N/A:P

D7870A13

N7870A01

CVE-2015-4146

Found and fixed unsafe code flow

5

AV:N/AC:L/Au:N/C:N/I:N/A:P

D7870A13

N7870A01

BRLY-2022-009,BRLY-2023-021

Found and fixed vulnerability for potential risk during PEI phase

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

D7870A13

N7870A01

BRLY-2022-160

Found and fixed unsafe code flow

6

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

D7870A13

N7870A01

PKfail

Untrusted Platform Key (PK) identified (PKfail)

N/A

D7870A13

N7870A01

BRLY-LOGOFAIL-2023-013, BRLK-LOGOFAIL-2023-021

Found and fixed unsafe code flow

6

AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

D7870A13

N7870A01

Subscribe to security updates

CL250 by OnLogic

OL 2024 080401

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-080401

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2024/10/15

Last Update Date: 2024/10/15

Affected Products:

Recommendation:

Update BIOS version to V2.08

OL 2024 090401

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-090401

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2024/10/15

Last Update Date: 2024/10/15

Affected Products:

Recommendation:

Update BIOS version to D8000A12

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2023-40238

OOB Write in RLE4 decode routine during BMP file processing in Insyde firmware.

5.5

CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

V2.05

V2.08

CVE-2021-41842,CVE-2024-27353 CVE-2024-25079,CVE-2024-25078 CVE-2022-36448,CVE-2022-35895 CVE-2022-35893,CVE-2022-35408 CVE-2022-34325,CVE-2022-24069 CVE-2022-24031,CVE-2022-24030 CVE-2021-45971,CVE-2021-45970 CVE-2021-45969,CVE-2021-43323 CVE-2021-42554,CVE-2021-41841 CVE-2021-41839,CVE-2021-41838 CVE-2021-41837,CVE-2021-33625, CVE-2022-46897,CVE-2022-35894

Fix issues discovered in InsydeH2O

7.5 ~ 8.2

CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

V2.05

V2.08

CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234

Fix ipv6 issues discovered in EDK2

7.5 ~ 8.3

CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

V2.05

V2.08

Karbon 800 Series by OnLogic

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2024-5290

Found and fixed an issue in Ubuntu wpa_supplicant.

8.8

CVSS:3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

D8000A11

D8000A12

K300 by OnLogic
Subscribe to security updates
Subscribe to security updates

OL 2025 0A0101

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2025-0A0101

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2025/06/13

Last Update Date: 2025/06/13

Affected Products:

Update BIOS version to AX301-A01-P_10.02.ROM

OL 2024 090101

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-090101

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2024/10/13

Last Update Date: 2025/02/03

Affected Products:

Recommendation:

Update BIOS version to VD7870A15.01

Vulnerability

Description

CVSS

CVSS Vector

Found version

Fixed version

CVE-2023-23583

Prevent from an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2023-39539,CVE-2023-39538

Fix potential risk when using a PNG/BMP logo

7.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2023-39537,CVE-2023-39536,CVE-2023-39535,CVE-2023-34470

Fix potential risk when using the local network

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2022-29974

Fix AMI NTFS driver buffer overflow issue.

4.3

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2024-45332

Fix potential risk

5.7

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2024-31068,CVE-2023-39368,CVE-2023-38575

Prevent from potentially causing denial of service or information disclosure via local access.

5.3-6.5

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2024-23984

Prevent from a privileged user to potentially enable information disclosure via local access.

6.8

CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2023-22655

Prevent from a privileged user to potentially enable escalation of privilege via local access.

4.3

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2023-34469

Fix AMI AptioV issue to prevent loss of confidentiality

4.6

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

Axial AX30X series by
OnLogic

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

BRLY-2022-009

Found and fixed vulnerability for potential risk during PEI phase

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

D7870A13

D7870A15.01

BRLY-2022-160

Found and fixed unsafe code flow

6

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

D7870A13

D7870A15.01

PKfail

Untrusted Platform Key (PK) identified (PKfail)

N/A

D7870A13

D7870A15.01

CL250 by OnLogic
Subscribe to security updates
Subscribe to security updates

OL 2024 080101

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-080101

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2024/10/13

Last Update Date: 2024/10/13

Affected Products:

Recommendation:

Update UEFI FW version to V1.58

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234

Fix ipv6 issues discovered in EDK2

7.5 ~ 8.3

CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

V1.55

V1.58

BRLY-2022-020

Fix potential vulnerability in Insyde H20

7.7

AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

V1.55

V1.58

BRLY-2023-005

Found unsafe code flow and fixed it

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

V1.55

V1.58

BRLY-2023-002

Found unsafe code flow and fixed it

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

V1.55

V1.58

Helix 400 Series
Subscribe to security updates

OL 2024 0B0002

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-0B0002

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2024/10/15

Last Update Date: 2024/10/15

Affected Products:

Recommendation:

Update BIOS version to X574I2T2_20G

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2023-45232,CVE-2023-45233, CVE-2023-45234,CVE-2023-45235

Found and fixed IPV6 related vulnerabilities for EDK2

7.5-8.3

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

X574I2T2.50

X574I2T2_20G

CVE-2023-45236, CVE-2023-45237

Found and fixed potential vulnerabilities for EDK2

5.5-5.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

X574I2T2.50

X574I2T2_20G

MK100-40 by OnLogic
Subscribe to security updates

OL 2024 090102

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-090102

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2024/10/15

Last Update Date: 2025/2/3

Affected Products:

Recommendation:

Update BIOS version to D7820T11

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

BRLY-2022-009

Found and fixed vulnerability for potential risk during PEI phase

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

D7820A09

D7820T11

PKFail

Untrusted Platform Key (PK) identified (PKfail)

N/A

N/A

D7820A09

D7820T11

BRLY-OemUnlockKeyLeak

The certificate is expired

N/A

N/A

D7820A09

D7820T11

ML350 by OnLogic
Subscribe to security updates

OL 2025 090103

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2025-090103

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2025/03/11

Last Update Date: 2025/03/11

Affected Products:

Recommendation:

Update BIOS version to D7820A11

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

BRLY-2022-009

Found and fixed vulnerability for potential risk during PEI phase

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

D7820A09

D7820A11

PKFail

Untrusted Platform Key (PK) identified (PKfail)

N/A

N/A

D7820A09

D7820A11

BRLY-OemUnlockKeyLeak

The certificate is expired

N/A

N/A

D7820A09

D7820A11

BRLY-2023-021

Found and fixed unsafe code flow

6

AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

D7820A09

D7820A11

BRLY-2022-160

Found and fixed unsafe code flow

6

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

D7820A09

D7820A11

ML350 by OnLogic
Subscribe to security updates

OL 2024 0B0001

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-0B0001

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2024/10/15

Last Update Date: 2024/10/15

Affected Products:

Recommendation:

Update BIOS version to W680D4U-2L2T-G5_21.11.OL10

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2024-5290

Found and fixed an issue in Ubuntu wpa_supplicant.

8.8

CVSS:3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

W680D4U-2L2T-G5_21.10.OL09

W680D4U-2L2T-G5_21.11.OL10

AC101 by OnLogic
Subscribe to security updates

OL 2025 080102

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2025-080102

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2025/3/11

Last Update Date: 2025/3/11

Affected Products:

Recommendation:

Update UEFI FW version to V1.59

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234, CVE-2023-45238

Fix ipv6 issues discovered in EDK2

6.3 ~ 8.3

CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

V1.55

V1.59

BRLY-2022-020

Fix potential vulnerability in Insyde H20

7.7

AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

V1.55

V1.59

BRLY-2023-005

Found unsafe code flow and fixed it

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

V1.55

V1.59

BRLY-2023-002

Found unsafe code flow and fixed it

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

V1.55

V1.59

BRLY-LOGOFAIL-2023-001, BRLY-LOGOFAIL-2023-002,BRLY-LOGOFAIL-2023-003,BRLY-LOGOFAIL-2023-008,BRLY-LOGOFAIL-2023-010, BRLY-LOGOFAIL-2023-011

Found unsafe code flow and fixed it

6-8

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

V1.55

V1.59

Helix 400 Series
Subscribe to security updates