Database/Firmware, BMC & network fabric

UEFI image parsers, AMI AptioV: Second LogoFAIL image-parser flaw in AMI AptioV BIOS
CVSS 7.5CVE-2023-39539Firmware, BMC & network fabricLogoFAILcurated
Impact
Second LogoFAIL image-parser flaw in AMI AptioV BIOS; same pre-Secure-Boot code execution primitive
Who can reach it
Local, ESP write
What to do
BIOS firmware update; on GPU nodes this means a full BIOS flash cycle with the node drained
References
Related entries
- UEFI image parsers, AMI AptioV: Unrestricted upload of a crafted BMP logo parsed by the BIOS at bootCVE-2023-39538 · UEFI image parsers, AMI AptioVHigh
- Juniper Junos OS Packet Forwarding Engine (MX Series): Improper handling of unusual conditions in the Packet ForwardingCVE-2023-44199 · Juniper Junos OS Packet Forwarding Engine (MX Series)High
- AMI AptioV UEFI BIOS (EDK II network stack, IPv6): An infinite loop when the firmware parses unknown options in an IPv6CVE-2023-45232 · AMI AptioV UEFI BIOS (EDK II network stack, IPv6)High
- EDK II NetworkPkg (IPv6 Destination Options header, PadN option parsing): Same shape as the unknown-option hang butCVE-2023-45233 · EDK II NetworkPkg (IPv6 Destination Options header, PadN option parsing)High
- EDK II NetworkPkg (TCP initial sequence number generation): The firmware's TCP initial sequence numbersCVE-2023-45236 · EDK II NetworkPkg (TCP initial sequence number generation)High
- EDK II NetworkPkg (PseudoRandom number generation used by the network stack): The weak PRNG behind the previous issueCVE-2023-45237 · EDK II NetworkPkg (PseudoRandom number generation used by the network stack)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.