Database/Firmware, BMC & network fabric

Insyde InsydeH2O BmpDecoderDxe: Crafted BMP logo copies data to a chosen address during DXE
CVE-2023-40238Firmware, BMC & network fabricLogoFAILcurated
Impact
Crafted BMP logo copies data to a chosen address during DXE — arbitrary write before Secure Boot
Who can reach it
Local, ESP write
What to do
Insyde kernel update shipped through each OEM; the CVSS understates it because the outcome is a firmware implant
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.