Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2025-080402
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2025/03/11
Last Update Date: 2025/03/11
Affected Products:
Update BIOS version to V2.15
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-0B0001
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2024/10/15
Last Update Date: 2024/10/15
Affected Products:
Recommendation:
Update BIOS version to W680D4U-2L2T-G5_21.11.OL10
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2025-080102
Type: Advisory
Fixed Vulnerabilities:
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2023-40238
OOB Write in RLE4 decode routine during BMP file processing in Insyde firmware.
5.5
CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
V2.05
V2.15
CVE-2021-41842,CVE-2024-27353 CVE-2024-25079,CVE-2024-25078 CVE-2022-36448,CVE-2022-35895 CVE-2022-35893,CVE-2022-35408 CVE-2022-34325,CVE-2022-24069 CVE-2022-24031,CVE-2022-24030 CVE-2021-45971,CVE-2021-45970 CVE-2021-45969,CVE-2021-43323 CVE-2021-42554,CVE-2021-41841 CVE-2021-41839,CVE-2021-41838 CVE-2021-41837,CVE-2021-33625, CVE-2022-46897,CVE-2022-35894
Fix issues discovered in InsydeH2O
7.5 ~ 8.2
CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
V2.05
V2.15
CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234
Fix ipv6 issues discovered in EDK2
7.5 ~ 8.3
CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
V2.05
V2.15
BRLY-2023-002
Found and fix unsafe code flow.
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
V2.05
V2.15
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2024-5290
Found and fixed an issue in Ubuntu wpa_supplicant.
8.8
CVSS:3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
W680D4U-2L2T-G5_21.10.OL09
W680D4U-2L2T-G5_21.11.OL10
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234, CVE-2023-45238
Fix ipv6 issues discovered in EDK2
6.3 ~ 8.3
CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
V1.55
V1.59
BRLY-2022-020
Fix potential vulnerability in Insyde H20
7.7
AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
V1.55
V1.59
BRLY-2023-005
Found unsafe code flow and fixed it
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
V1.55
V1.59
BRLY-2023-002
Found unsafe code flow and fixed it
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
V1.55
V1.59
BRLY-LOGOFAIL-2023-001, BRLY-LOGOFAIL-2023-002,BRLY-LOGOFAIL-2023-003,BRLY-LOGOFAIL-2023-008,BRLY-LOGOFAIL-2023-010, BRLY-LOGOFAIL-2023-011
Found unsafe code flow and fixed it
6-8
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
V1.55
V1.59
First Public Date: 2025/3/11
Last Update Date: 2025/3/11
Affected Products:
Recommendation:
Update UEFI FW version to V1.59
Vulnerability
Mitigation for KARBON 800 series
Advisory
Critical
10/13/2024
10/13/2024
Helix 400 series
Mitigation for Helix 400 series
Advisory
Critical
10/13/2024
10/13/2024
CL250
Mitigation for CL250
Advisory
Medium
10/13/2024
02/03/2025
ML350
Mitigation for ML350
Advisory
Medium
10/15/2024
02/03/2024
KARBON 300
Mitigation for KARBON 300
Advisory
High
10/15/2024
10/15/2024
AC101
Mitigation for AC101
Advisory
High
10/15/2024
10/15/2024
MK100B-40
Mitigation for MK100B-40
Advisory
High
10/15/2024
02/03/2024
KARBON 800 series
Mitigation for KARBON 800 series
AXIAL AX30X series
Mitigation for AXIAL AX30X series
KARBON 800 series
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-080101
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2024/10/13
Last Update Date: 2024/10/13
Affected Products:
Recommendation:
Update UEFI FW version to V1.58
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-080401
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2024/10/15
Last Update Date: 2024/10/15
Affected Products:
Recommendation:
Update BIOS version to V2.08
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-0B0002
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2024/10/15
Last Update Date: 2024/10/15
Affected Products:
Recommendation:
Update BIOS version to X574I2T2_20G
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2025-090103
Type: Advisory
Fixed Vulnerabilities:
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-090102
Type: Advisory
Fixed Vulnerabilities:
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-090101
Type: Advisory
Fixed Vulnerabilities:
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2024-090401
Type: Advisory
Fixed Vulnerabilities:
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234
Fix ipv6 issues discovered in EDK2
7.5 ~ 8.3
CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
V1.55
V1.58
BRLY-2022-020
Fix potential vulnerability in Insyde H20
7.7
AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
V1.55
V1.58
BRLY-2023-005
Found unsafe code flow and fixed it
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
V1.55
V1.58
BRLY-2023-002
Found unsafe code flow and fixed it
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
V1.55
V1.58
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2023-40238
OOB Write in RLE4 decode routine during BMP file processing in Insyde firmware.
5.5
CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
V2.05
V2.08
CVE-2021-41842,CVE-2024-27353 CVE-2024-25079,CVE-2024-25078 CVE-2022-36448,CVE-2022-35895 CVE-2022-35893,CVE-2022-35408 CVE-2022-34325,CVE-2022-24069 CVE-2022-24031,CVE-2022-24030 CVE-2021-45971,CVE-2021-45970 CVE-2021-45969,CVE-2021-43323 CVE-2021-42554,CVE-2021-41841 CVE-2021-41839,CVE-2021-41838 CVE-2021-41837,CVE-2021-33625, CVE-2022-46897,CVE-2022-35894
Fix issues discovered in InsydeH2O
7.5 ~ 8.2
CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
V2.05
V2.08
CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234
Fix ipv6 issues discovered in EDK2
7.5 ~ 8.3
CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
V2.05
V2.08
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2023-45232,CVE-2023-45233, CVE-2023-45234,CVE-2023-45235
Found and fixed IPV6 related vulnerabilities for EDK2
7.5-8.3
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
X574I2T2.50
X574I2T2_20G
CVE-2023-45236, CVE-2023-45237
Found and fixed potential vulnerabilities for EDK2
5.5-5.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
X574I2T2.50
X574I2T2_20G
Advisory
Critical
03/11/2025
03/11/2025
Helix 400 series
Mitigation for Helix 400 series
Advisory
Critical
03/11/2025
03/11/2025
CL250
Mitigation for CL250
Advisory
Medium
03/11/2025
03/11/2025
ML350
Mititgation for ML350
Advisory
Medium
03/11/2025
03/11/2025
Advisory
Critical
06/13/2025
06/13/2025
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
BRLY-2022-009
Found and fixed vulnerability for potential risk during PEI phase
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
D7820A09
D7820A11
PKFail
Untrusted Platform Key (PK) identified (PKfail)
N/A
N/A
D7820A09
D7820A11
BRLY-OemUnlockKeyLeak
The certificate is expired
N/A
N/A
D7820A09
D7820A11
BRLY-2023-021
Found and fixed unsafe code flow
6
AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
D7820A09
D7820A11
BRLY-2022-160
Found and fixed unsafe code flow
6
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
D7820A09
D7820A11
First Public Date: 2025/03/11
Last Update Date: 2025/03/11
Affected Products:
Recommendation:
Update BIOS version to D7820A11
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
BRLY-2022-009
Found and fixed vulnerability for potential risk during PEI phase
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
D7820A09
D7820T11
PKFail
Untrusted Platform Key (PK) identified (PKfail)
N/A
N/A
D7820A09
D7820T11
BRLY-OemUnlockKeyLeak
The certificate is expired
N/A
N/A
D7820A09
D7820T11
First Public Date: 2024/10/15
Last Update Date: 2025/2/3
Affected Products:
Recommendation:
Update BIOS version to D7820T11
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
BRLY-2022-009
Found and fixed vulnerability for potential risk during PEI phase
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
D7870A13
D7870A15.01
BRLY-2022-160
Found and fixed unsafe code flow
6
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
D7870A13
D7870A15.01
PKfail
Untrusted Platform Key (PK) identified (PKfail)
N/A
D7870A13
D7870A15.01
First Public Date: 2024/10/13
Last Update Date: 2025/02/03
Affected Products:
Recommendation:
Update BIOS version to VD7870A15.01
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2024-5290
Found and fixed an issue in Ubuntu wpa_supplicant.
8.8
CVSS:3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
D8000A11
D8000A12
First Public Date: 2024/10/15
Last Update Date: 2024/10/15
Affected Products:
Recommendation:
Update BIOS version to D8000A12
Vulnerability
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2025-0A0101
Type: Advisory
Fixed Vulnerabilities:
Description
CVSS
CVSS Vector
Found version
Fixed version
CVE-2023-23583
Prevent from an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2023-39539,CVE-2023-39538
Fix potential risk when using a PNG/BMP logo
7.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2023-39537,CVE-2023-39536,CVE-2023-39535,CVE-2023-34470
Fix potential risk when using the local network
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2022-29974
Fix AMI NTFS driver buffer overflow issue.
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2024-45332
Fix potential risk
5.7
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2024-31068,CVE-2023-39368,CVE-2023-38575
Prevent from potentially causing denial of service or information disclosure via local access.
5.3-6.5
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2024-23984
Prevent from a privileged user to potentially enable information disclosure via local access.
6.8
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2023-22655
Prevent from a privileged user to potentially enable escalation of privilege via local access.
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
CVE-2023-34469
Fix AMI AptioV issue to prevent loss of confidentiality
4.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AX301-A01-P_10.01.ROM
AX301-A01-P_10.02.ROM
First Public Date: 2025/06/13
Last Update Date: 2025/06/13
Affected Products:
Update BIOS version to AX301-A01-P_10.02.ROM
Vulnerability
Description:
Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.
OnLogic Security Advisory ID: OL-2025-090102
Type: Advisory
Fixed Vulnerabilities:
First Public Date: 2025/03/11
Last Update Date: 2025/03/11
Affected Products:
Update BIOS version to N7870A01
Vulnerability
Description
CVSS Base Score
CVSS Vector String
Found version
Fixed version
CVE-2014-3686
Found and fixed unsafe code flow
6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
D7870A13
N7870A01
CVE-2015-0210
Found and fixed unsafe code flow
5.9
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
D7870A13
N7870A01
CVE-2015-1863
Found and fixed unsafe code flow
5.8
AV:A/AC:L/Au:N/C:P/I:P/A:P
D7870A13
N7870A01
CVE-2015-4141
Found and fixed unsafe code flow
4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P
D7870A13
N7870A01
CVE-2015-4142
Found and fixed unsafe code flow
4.3
V:N/AC:M/Au:N/C:N/I:N/A:P
D7870A13
N7870A01
CVE-2015-4143
Found and fixed unsafe code flow
5
AV:N/AC:L/Au:N/C:N/I:N/A:P
D7870A13
N7870A01
CVE-2015-4144
Found and fixed unsafe code flow
5
AV:N/AC:L/Au:N/C:N/I:N/A:P
D7870A13
N7870A01
CVE-2015-4145
Found and fixed unsafe code flow
5
AV:N/AC:L/Au:N/C:N/I:N/A:P
D7870A13
N7870A01
CVE-2015-4146
Found and fixed unsafe code flow
5
AV:N/AC:L/Au:N/C:N/I:N/A:P
D7870A13
N7870A01
BRLY-2022-009,BRLY-2023-021
Found and fixed vulnerability for potential risk during PEI phase
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
D7870A13
N7870A01
BRLY-2022-160
Found and fixed unsafe code flow
6
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
D7870A13
N7870A01
PKfail
Untrusted Platform Key (PK) identified (PKfail)
N/A
D7870A13
N7870A01
BRLY-LOGOFAIL-2023-013, BRLK-LOGOFAIL-2023-021
Found and fixed unsafe code flow
6
AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
D7870A13
N7870A01