Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2025-080402
Type: Advisory
Fixed Vulnerabilities:
Critical
03/11/2025
03/11/2025
Helix 400 series
Mitigation for Helix 400 series
Advisory
Critical
03/11/2025
03/11/2025
CL250
Mitigation for CL250
Advisory
Medium
03/11/2025
03/11/2025
ML350
Mititgation for ML350
Advisory
Medium
03/11/2025
03/11/2025
Critical
06/13/2025
06/13/2025
KARBON 800 series
Mitigation for KARBON 800 series
Advisory
Critical
10/13/2024
10/13/2024
Helix 400 series
Mitigation for Helix 400 series
Advisory
Critical
10/13/2024
10/13/2024
CL250
Mitigation for CL250
Advisory
Medium
10/13/2024
02/03/2025
ML350
Mitigation for ML350
Advisory
Medium
10/15/2024
02/03/2024
KARBON 300
Mitigation for KARBON 300
Advisory
High
10/15/2024
10/15/2024
AC101
Mitigation for AC101
Advisory
High
10/15/2024
10/15/2024
MK100B-40
Mitigation for MK100B-40
Advisory
High
10/15/2024
02/03/2024
KARBON 800 series
Mitigation for KARBON 800 series
AXIAL AX30X series
Mitigation for AXIAL AX30X series
Advisory
Advisory
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2023-40238
OOB Write in RLE4 decode routine during BMP file processing in Insyde firmware.
5.5
CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
V2.05
V2.15
CVE-2021-41842,CVE-2024-27353 CVE-2024-25079,CVE-2024-25078 CVE-2022-36448,CVE-2022-35895 CVE-2022-35893,CVE-2022-35408 CVE-2022-34325,CVE-2022-24069 CVE-2022-24031,CVE-2022-24030 CVE-2021-45971,CVE-2021-45970 CVE-2021-45969,CVE-2021-43323 CVE-2021-42554,CVE-2021-41841 CVE-2021-41839,CVE-2021-41838 CVE-2021-41837,CVE-2021-33625, CVE-2022-46897,CVE-2022-35894
Fix issues discovered in InsydeH2O
7.5 ~ 8.2
CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
V2.05
V2.15
CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234
Fix ipv6 issues discovered in EDK2
7.5 ~ 8.3
CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
V2.05
V2.15
BRLY-2023-002
Found and fix unsafe code flow.
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
V2.05
V2.15
First Public Date: 2025/03/11
Last Update Date: 2025/03/11
Affected Products:
Update BIOS version to V2.15
Vulnerability
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2025-090102
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2025/03/11
Last Update Date: 2025/03/11
Affected Products:
Update BIOS version to N7870A01
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2014-3686
Found and fixed unsafe code flow
6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
D7870A13
N7870A01
CVE-2015-0210
Found and fixed unsafe code flow
5.9
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
D7870A13
N7870A01
CVE-2015-1863
Found and fixed unsafe code flow
5.8
AV:A/AC:L/Au:N/C:P/I:P/A:P
D7870A13
N7870A01
CVE-2015-4141
Found and fixed unsafe code flow
4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P
D7870A13
N7870A01
CVE-2015-4142
Found and fixed unsafe code flow
4.3
V:N/AC:M/Au:N/C:N/I:N/A:P
D7870A13
N7870A01
CVE-2015-4143
Found and fixed unsafe code flow
5
AV:N/AC:L/Au:N/C:N/I:N/A:P
D7870A13
N7870A01
CVE-2015-4144
Found and fixed unsafe code flow
5
AV:N/AC:L/Au:N/C:N/I:N/A:P
D7870A13
N7870A01
CVE-2015-4145
Found and fixed unsafe code flow
5
AV:N/AC:L/Au:N/C:N/I:N/A:P
D7870A13
N7870A01
CVE-2015-4146
Found and fixed unsafe code flow
5
AV:N/AC:L/Au:N/C:N/I:N/A:P
D7870A13
N7870A01
BRLY-2022-009,BRLY-2023-021
Found and fixed vulnerability for potential risk during PEI phase
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
D7870A13
N7870A01
BRLY-2022-160
Found and fixed unsafe code flow
6
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
D7870A13
N7870A01
PKfail
Untrusted Platform Key (PK) identified (PKfail)
N/A
D7870A13
N7870A01
BRLY-LOGOFAIL-2023-013, BRLK-LOGOFAIL-2023-021
Found and fixed unsafe code flow
6
AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
D7870A13
N7870A01
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-080401
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2024/10/15
Last Update Date: 2024/10/15
Affected Products:
Recommendation:
Update BIOS version to V2.08
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-090401
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2024/10/15
Last Update Date: 2024/10/15
Affected Products:
Recommendation:
Update BIOS version to D8000A12
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2023-40238
OOB Write in RLE4 decode routine during BMP file processing in Insyde firmware.
5.5
CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
V2.05
V2.08
CVE-2021-41842,CVE-2024-27353 CVE-2024-25079,CVE-2024-25078 CVE-2022-36448,CVE-2022-35895 CVE-2022-35893,CVE-2022-35408 CVE-2022-34325,CVE-2022-24069 CVE-2022-24031,CVE-2022-24030 CVE-2021-45971,CVE-2021-45970 CVE-2021-45969,CVE-2021-43323 CVE-2021-42554,CVE-2021-41841 CVE-2021-41839,CVE-2021-41838 CVE-2021-41837,CVE-2021-33625, CVE-2022-46897,CVE-2022-35894
Fix issues discovered in InsydeH2O
7.5 ~ 8.2
CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
V2.05
V2.08
CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234
Fix ipv6 issues discovered in EDK2
7.5 ~ 8.3
CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
V2.05
V2.08
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2024-5290
Found and fixed an issue in Ubuntu wpa_supplicant.
8.8
CVSS:3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
D8000A11
D8000A12
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2025-0A0101
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2025/06/13
Last Update Date: 2025/06/13
Affected Products:
Update BIOS version to AX301-A01-P_10.02.ROM
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-090101
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2024/10/13
Last Update Date: 2025/02/03
Affected Products:
Recommendation:
Update BIOS version to VD7870A15.01
Vulnerability
Description
CVSS
CVSS Vector
Found version
Fixed version
CVE-2023-23583
Prevent from an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2023-39539,CVE-2023-39538
Fix potential risk when using a PNG/BMP logo
7.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2023-39537,CVE-2023-39536,CVE-2023-39535,CVE-2023-34470
Fix potential risk when using the local network
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2022-29974
Fix AMI NTFS driver buffer overflow issue.
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2024-45332
Fix potential risk
5.7
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2024-31068,CVE-2023-39368,CVE-2023-38575
Prevent from potentially causing denial of service or information disclosure via local access.
5.3-6.5
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2024-23984
Prevent from a privileged user to potentially enable information disclosure via local access.
6.8
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2023-22655
Prevent from a privileged user to potentially enable escalation of privilege via local access.
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2023-34469
Fix AMI AptioV issue to prevent loss of confidentiality
4.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
BRLY-2022-009
Found and fixed vulnerability for potential risk during PEI phase
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
D7870A13
D7870A15.01
BRLY-2022-160
Found and fixed unsafe code flow
6
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
D7870A13
D7870A15.01
PKfail
Untrusted Platform Key (PK) identified (PKfail)
N/A
D7870A13
D7870A15.01
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-080101
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2024/10/13
Last Update Date: 2024/10/13
Affected Products:
Recommendation:
Update UEFI FW version to V1.58
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234
Fix ipv6 issues discovered in EDK2
7.5 ~ 8.3
CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
V1.55
V1.58
BRLY-2022-020
Fix potential vulnerability in Insyde H20
7.7
AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
V1.55
V1.58
BRLY-2023-005
Found unsafe code flow and fixed it
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
V1.55
V1.58
BRLY-2023-002
Found unsafe code flow and fixed it
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
V1.55
V1.58
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-0B0002
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2024/10/15
Last Update Date: 2024/10/15
Affected Products:
Recommendation:
Update BIOS version to X574I2T2_20G
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2023-45232,CVE-2023-45233, CVE-2023-45234,CVE-2023-45235
Found and fixed IPV6 related vulnerabilities for EDK2
7.5-8.3
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
X574I2T2.50
X574I2T2_20G
CVE-2023-45236, CVE-2023-45237
Found and fixed potential vulnerabilities for EDK2
5.5-5.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
X574I2T2.50
X574I2T2_20G
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-090102
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2024/10/15
Last Update Date: 2025/2/3
Affected Products:
Recommendation:
Update BIOS version to D7820T11
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
BRLY-2022-009
Found and fixed vulnerability for potential risk during PEI phase
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
D7820A09
D7820T11
PKFail
Untrusted Platform Key (PK) identified (PKfail)
N/A
N/A
D7820A09
D7820T11
BRLY-OemUnlockKeyLeak
The certificate is expired
N/A
N/A
D7820A09
D7820T11
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2025-090103
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2025/03/11
Last Update Date: 2025/03/11
Affected Products:
Recommendation:
Update BIOS version to D7820A11
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
BRLY-2022-009
Found and fixed vulnerability for potential risk during PEI phase
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
D7820A09
D7820A11
PKFail
Untrusted Platform Key (PK) identified (PKfail)
N/A
N/A
D7820A09
D7820A11
BRLY-OemUnlockKeyLeak
The certificate is expired
N/A
N/A
D7820A09
D7820A11
BRLY-2023-021
Found and fixed unsafe code flow
6
AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
D7820A09
D7820A11
BRLY-2022-160
Found and fixed unsafe code flow
6
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
D7820A09
D7820A11
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-0B0001
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2024/10/15
Last Update Date: 2024/10/15
Affected Products:
Recommendation:
Update BIOS version to W680D4U-2L2T-G5_21.11.OL10
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2024-5290
Found and fixed an issue in Ubuntu wpa_supplicant.
8.8
CVSS:3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
W680D4U-2L2T-G5_21.10.OL09
W680D4U-2L2T-G5_21.11.OL10
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2025-080102
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2025/3/11
Last Update Date: 2025/3/11
Affected Products:
Recommendation:
Update UEFI FW version to V1.59
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234, CVE-2023-45238
Fix ipv6 issues discovered in EDK2
6.3 ~ 8.3
CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
V1.55
V1.59
BRLY-2022-020
Fix potential vulnerability in Insyde H20
7.7
AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
V1.55
V1.59
BRLY-2023-005
Found unsafe code flow and fixed it
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
V1.55
V1.59
BRLY-2023-002
Found unsafe code flow and fixed it
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
V1.55
V1.59
BRLY-LOGOFAIL-2023-001, BRLY-LOGOFAIL-2023-002,BRLY-LOGOFAIL-2023-003,BRLY-LOGOFAIL-2023-008,BRLY-LOGOFAIL-2023-010, BRLY-LOGOFAIL-2023-011
Found unsafe code flow and fixed it
6-8
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
V1.55
V1.59