VDB
WID-SEC-W-2023-3068
WID-SEC-W-2023-3068
PUBLISHED
CVSS 6.900000095367432 MEDIUM
Das BIOS ist die Firmware bei IBM PC kompatiblen Computern. InsydeH2O UEFI BIOS ist eine proprietäre, lizenzierte UEFI-BIOS-Firmware, die Intel und AMD basierte Computer unterstützt.
Risk Scores
CVSS v4.0
6.900000095367432
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Insyde UEFI Firmware kernel 5.6 Version 05.60.47 | ||
| Insyde UEFI Firmware kernel 5.3 <Version 05.37.47 | ||
| Insyde UEFI Firmware kernel 5.3 Version 05.37.47 | ||
| Lenovo BIOS | ||
| Dell PowerScale <12.4.1 | ||
| Insyde UEFI Firmware kernel 5.5 Version 05.53.47 | ||
| HP Computer | ||
| Insyde UEFI Firmware kernel 5.2 Version 05.28.47 | ||
| Insyde UEFI Firmware kernel 5.6 <Version 05.60.47 | ||
| Insyde UEFI Firmware kernel 5.4 <Version 05.45.47 | ||
| Dell PowerScale 12.4.1 | ||
| Insyde UEFI Firmware kernel 5.2 <Version 05.28.47 | ||
| Insyde UEFI Firmware kernel 5.4 Version 05.45.47 | ||
| Insyde UEFI Firmware kernel 5.5 <Version 05.53.47 |
Exploit Intelligence
- PoC for CVE-2023-39539 in Cacti 1.2.22 (github-poc)
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3068.json (circl)
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-3068 (circl)
- https://binarly.io/posts/finding_logofail_the_dangers_of_image_parsing_during_system_boot/index.html (circl)
- https://www.kb.cert.org/vuls/id/811862 (circl)
- https://www.insyde.com/security-pledge/SA-2023053 (circl)
- https://support.lenovo.com/us/en/product_security/LEN-145284 (circl)
- https://github.com/advisories/GHSA-87fm-wcxm-mcmx (circl)
- https://github.com/advisories/GHSA-xhch-7j88-pg68 (circl)
- https://support.hp.com/us-en/document/ish_10832513-10832541-16/HPSBHF03950 (circl)
…and 1 more exploits
Timeline
- Dec 6, 2023 CVE Published
- Dec 16, 2024 CVE Updated
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3068.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-3068 advisory
- https://binarly.io/posts/finding_logofail_the_dangers_of_image_parsing_during_system_boot/index.html url
- https://www.kb.cert.org/vuls/id/811862 url
- https://www.insyde.com/security-pledge/SA-2023053 url
- https://support.lenovo.com/us/en/product_security/LEN-145284 url
- https://github.com/advisories/GHSA-87fm-wcxm-mcmx url
- https://github.com/advisories/GHSA-xhch-7j88-pg68 url
- https://support.hp.com/us-en/document/ish_10832513-10832541-16/HPSBHF03950 url
- https://www.dell.com/support/kbdoc/de-de/000260794/dsa-2024-455-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities url