All pages
Powered by GitBook
1 of 13

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

OL 2025 080402

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2025-080402

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2025/03/11

Last Update Date: 2025/03/11

Affected Products:

Update BIOS version to V2.15

OL 2024 0B0001

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-0B0001

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2024/10/15

Last Update Date: 2024/10/15

Affected Products:

Recommendation:

Update BIOS version to W680D4U-2L2T-G5_21.11.OL10

OL 2025 080102

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2025-080102

Type: Advisory

Fixed Vulnerabilities:

Security Advisories

Advisory ID
Impact
Title
Type
Severity
Published
Last Updated

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2023-40238

OOB Write in RLE4 decode routine during BMP file processing in Insyde firmware.

5.5

CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

V2.05

V2.15

CVE-2021-41842,CVE-2024-27353 CVE-2024-25079,CVE-2024-25078 CVE-2022-36448,CVE-2022-35895 CVE-2022-35893,CVE-2022-35408 CVE-2022-34325,CVE-2022-24069 CVE-2022-24031,CVE-2022-24030 CVE-2021-45971,CVE-2021-45970 CVE-2021-45969,CVE-2021-43323 CVE-2021-42554,CVE-2021-41841 CVE-2021-41839,CVE-2021-41838 CVE-2021-41837,CVE-2021-33625, CVE-2022-46897,CVE-2022-35894

Fix issues discovered in InsydeH2O

7.5 ~ 8.2

CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

V2.05

V2.15

CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234

Fix ipv6 issues discovered in EDK2

7.5 ~ 8.3

CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

V2.05

V2.15

BRLY-2023-002

Found and fix unsafe code flow.

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

V2.05

V2.15

Subscribe to security updates

Karbon 800 Series by OnLogic

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2024-5290

Found and fixed an issue in Ubuntu wpa_supplicant.

8.8

CVSS:3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

W680D4U-2L2T-G5_21.10.OL09

W680D4U-2L2T-G5_21.11.OL10

Subscribe to security updates

AC101 by OnLogic

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234, CVE-2023-45238

Fix ipv6 issues discovered in EDK2

6.3 ~ 8.3

CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

V1.55

V1.59

BRLY-2022-020

Fix potential vulnerability in Insyde H20

7.7

AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

V1.55

V1.59

BRLY-2023-005

Found unsafe code flow and fixed it

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

V1.55

V1.59

BRLY-2023-002

Found unsafe code flow and fixed it

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

V1.55

V1.59

BRLY-LOGOFAIL-2023-001, BRLY-LOGOFAIL-2023-002,BRLY-LOGOFAIL-2023-003,BRLY-LOGOFAIL-2023-008,BRLY-LOGOFAIL-2023-010, BRLY-LOGOFAIL-2023-011

Found unsafe code flow and fixed it

6-8

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

V1.55

V1.59

First Public Date: 2025/3/11

Last Update Date: 2025/3/11

Affected Products:

  • Helix 400 Series

Recommendation:

Update UEFI FW version to V1.59

Vulnerability

Mitigation for KARBON 800 series

Advisory

Critical

10/13/2024

10/13/2024

Helix 400 series

Mitigation for Helix 400 series

Advisory

Critical

10/13/2024

10/13/2024

CL250

Mitigation for CL250

Advisory

Medium

10/13/2024

02/03/2025

ML350

Mitigation for ML350

Advisory

Medium

10/15/2024

02/03/2024

KARBON 300

Mitigation for KARBON 300

Advisory

High

10/15/2024

10/15/2024

AC101

Mitigation for AC101

Advisory

High

10/15/2024

10/15/2024

MK100B-40

Mitigation for MK100B-40

Advisory

High

10/15/2024

02/03/2024

Advisory ID
Impact
Title
Type
Severity
Published
Last Updated

KARBON 800 series

Mitigation for KARBON 800 series

Advisory ID
Impact
Title
Type
Severity
Published
Last Updated

AXIAL AX30X series

Mitigation for AXIAL AX30X series

OL-2024-080401

Subscribe to security updates

2024 - October

KARBON 800 series

2025 - March

2025 - June

OL 2024 080101

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-080101

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2024/10/13

Last Update Date: 2024/10/13

Affected Products:

Recommendation:

Update UEFI FW version to V1.58

OL 2024 080401

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-080401

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2024/10/15

Last Update Date: 2024/10/15

Affected Products:

Recommendation:

Update BIOS version to V2.08

OL 2024 0B0002

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-0B0002

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2024/10/15

Last Update Date: 2024/10/15

Affected Products:

Recommendation:

Update BIOS version to X574I2T2_20G

OL 2025 090103

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2025-090103

Type: Advisory

Fixed Vulnerabilities:

OL 2024 090102

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-090102

Type: Advisory

Fixed Vulnerabilities:

OL 2024 090101

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-090101

Type: Advisory

Fixed Vulnerabilities:

OL 2024 090401

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2024-090401

Type: Advisory

Fixed Vulnerabilities:

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234

Fix ipv6 issues discovered in EDK2

7.5 ~ 8.3

CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

V1.55

V1.58

BRLY-2022-020

Fix potential vulnerability in Insyde H20

7.7

AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

V1.55

V1.58

BRLY-2023-005

Found unsafe code flow and fixed it

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

V1.55

V1.58

BRLY-2023-002

Found unsafe code flow and fixed it

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

V1.55

V1.58

Subscribe to security updates

Helix 400 Series

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2023-40238

OOB Write in RLE4 decode routine during BMP file processing in Insyde firmware.

5.5

CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

V2.05

V2.08

CVE-2021-41842,CVE-2024-27353 CVE-2024-25079,CVE-2024-25078 CVE-2022-36448,CVE-2022-35895 CVE-2022-35893,CVE-2022-35408 CVE-2022-34325,CVE-2022-24069 CVE-2022-24031,CVE-2022-24030 CVE-2021-45971,CVE-2021-45970 CVE-2021-45969,CVE-2021-43323 CVE-2021-42554,CVE-2021-41841 CVE-2021-41839,CVE-2021-41838 CVE-2021-41837,CVE-2021-33625, CVE-2022-46897,CVE-2022-35894

Fix issues discovered in InsydeH2O

7.5 ~ 8.2

CVSS:3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

V2.05

V2.08

CVE-2023-45230,CVE-2023-45232, CVE-2023-45233,CVE-2023-45234

Fix ipv6 issues discovered in EDK2

7.5 ~ 8.3

CVSS:3.1 /AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

V2.05

V2.08

Subscribe to security updates

Karbon 800 Series by OnLogic

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2023-45232,CVE-2023-45233, CVE-2023-45234,CVE-2023-45235

Found and fixed IPV6 related vulnerabilities for EDK2

7.5-8.3

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

X574I2T2.50

X574I2T2_20G

CVE-2023-45236, CVE-2023-45237

Found and fixed potential vulnerabilities for EDK2

5.5-5.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

X574I2T2.50

X574I2T2_20G

Subscribe to security updates

MK100-40 by OnLogic

Advisory

Critical

03/11/2025

03/11/2025

OL-2025-080102

Helix 400 series

Mitigation for Helix 400 series

Advisory

Critical

03/11/2025

03/11/2025

OL-2025-090102

CL250

Mitigation for CL250

Advisory

Medium

03/11/2025

03/11/2025

OL-2025-090103

ML350

Mititgation for ML350

Advisory

Medium

03/11/2025

03/11/2025

Advisory

Critical

06/13/2025

06/13/2025

OL-2024-080101
OL-2024-090101
OL-2024-090102
OL-2024-090401
OL-2024-0B0001
OL-2024-0B0002
OL-2025-080402
OL-2025-0A0101
Subscribe to security updates

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

BRLY-2022-009

Found and fixed vulnerability for potential risk during PEI phase

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

D7820A09

D7820A11

PKFail

Untrusted Platform Key (PK) identified (PKfail)

N/A

N/A

D7820A09

D7820A11

BRLY-OemUnlockKeyLeak

The certificate is expired

N/A

N/A

D7820A09

D7820A11

BRLY-2023-021

Found and fixed unsafe code flow

6

AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

D7820A09

D7820A11

BRLY-2022-160

Found and fixed unsafe code flow

6

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

D7820A09

D7820A11

First Public Date: 2025/03/11

Last Update Date: 2025/03/11

Affected Products:

  • ML350 by OnLogic

Recommendation:

Update BIOS version to D7820A11

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

BRLY-2022-009

Found and fixed vulnerability for potential risk during PEI phase

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

D7820A09

D7820T11

PKFail

Untrusted Platform Key (PK) identified (PKfail)

N/A

N/A

D7820A09

D7820T11

BRLY-OemUnlockKeyLeak

The certificate is expired

N/A

N/A

D7820A09

D7820T11

First Public Date: 2024/10/15

Last Update Date: 2025/2/3

Affected Products:

  • ML350 by OnLogic

Recommendation:

Update BIOS version to D7820T11

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

BRLY-2022-009

Found and fixed vulnerability for potential risk during PEI phase

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

D7870A13

D7870A15.01

BRLY-2022-160

Found and fixed unsafe code flow

6

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

D7870A13

D7870A15.01

PKfail

Untrusted Platform Key (PK) identified (PKfail)

N/A

D7870A13

D7870A15.01

First Public Date: 2024/10/13

Last Update Date: 2025/02/03

Affected Products:

  • CL250 by OnLogic

Recommendation:

Update BIOS version to VD7870A15.01

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2024-5290

Found and fixed an issue in Ubuntu wpa_supplicant.

8.8

CVSS:3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

D8000A11

D8000A12

First Public Date: 2024/10/15

Last Update Date: 2024/10/15

Affected Products:

  • K300 by OnLogic

Recommendation:

Update BIOS version to D8000A12

Vulnerability

OL 2025 0A0101

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2025-0A0101

Type: Advisory

Fixed Vulnerabilities:

Subscribe to security updates
Subscribe to security updates
Subscribe to security updates
Subscribe to security updates

Description

CVSS

CVSS Vector

Found version

Fixed version

CVE-2023-23583

Prevent from an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2023-39539,CVE-2023-39538

Fix potential risk when using a PNG/BMP logo

7.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2023-39537,CVE-2023-39536,CVE-2023-39535,CVE-2023-34470

Fix potential risk when using the local network

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2022-29974

Fix AMI NTFS driver buffer overflow issue.

4.3

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2024-45332

Fix potential risk

5.7

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2024-31068,CVE-2023-39368,CVE-2023-38575

Prevent from potentially causing denial of service or information disclosure via local access.

5.3-6.5

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2024-23984

Prevent from a privileged user to potentially enable information disclosure via local access.

6.8

CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2023-22655

Prevent from a privileged user to potentially enable escalation of privilege via local access.

4.3

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

CVE-2023-34469

Fix AMI AptioV issue to prevent loss of confidentiality

4.6

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AX301-A01-P_10.01.ROM

AX301-A01-P_10.02.ROM

First Public Date: 2025/06/13

Last Update Date: 2025/06/13

Affected Products:

  • Axial AX30X series by OnLogic

Update BIOS version to AX301-A01-P_10.02.ROM

Vulnerability

OL 2025 090102

Description:

Fix several critical vulnerabilities of specified BIOS versions, preventing damage from those vulnerabilities being exploited.

OnLogic Security Advisory ID: OL-2025-090102

Type: Advisory

Fixed Vulnerabilities:

First Public Date: 2025/03/11

Last Update Date: 2025/03/11

Affected Products:

Update BIOS version to N7870A01

Subscribe to security updates

Vulnerability

Description

CVSS Base Score

CVSS Vector String

Found version

Fixed version

CVE-2014-3686

Found and fixed unsafe code flow

6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

D7870A13

N7870A01

CVE-2015-0210

Found and fixed unsafe code flow

5.9

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

D7870A13

N7870A01

CVE-2015-1863

Found and fixed unsafe code flow

5.8

AV:A/AC:L/Au:N/C:P/I:P/A:P

D7870A13

N7870A01

CVE-2015-4141

Found and fixed unsafe code flow

4.3

AV:N/AC:M/Au:N/C:N/I:N/A:P

D7870A13

N7870A01

CVE-2015-4142

Found and fixed unsafe code flow

4.3

V:N/AC:M/Au:N/C:N/I:N/A:P

D7870A13

N7870A01

CVE-2015-4143

Found and fixed unsafe code flow

5

AV:N/AC:L/Au:N/C:N/I:N/A:P

D7870A13

N7870A01

CVE-2015-4144

Found and fixed unsafe code flow

5

AV:N/AC:L/Au:N/C:N/I:N/A:P

D7870A13

N7870A01

CVE-2015-4145

Found and fixed unsafe code flow

5

AV:N/AC:L/Au:N/C:N/I:N/A:P

D7870A13

N7870A01

CVE-2015-4146

Found and fixed unsafe code flow

5

AV:N/AC:L/Au:N/C:N/I:N/A:P

D7870A13

N7870A01

BRLY-2022-009,BRLY-2023-021

Found and fixed vulnerability for potential risk during PEI phase

8.2

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

D7870A13

N7870A01

BRLY-2022-160

Found and fixed unsafe code flow

6

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

D7870A13

N7870A01

PKfail

Untrusted Platform Key (PK) identified (PKfail)

N/A

D7870A13

N7870A01

BRLY-LOGOFAIL-2023-013, BRLK-LOGOFAIL-2023-021

Found and fixed unsafe code flow

6

AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

D7870A13

N7870A01

CL250 by OnLogic
Subscribe to security updates