BRLY-LOGOFAIL-2023-014
Out-of-bounds Read in DXE driver.
CVE ID
-
Vendors Affected
LogoFAIL
Products Affected
AMITSE
Summary
BINARLY efiXplorer team has discovered a OOB Read vulnerability in DXE driver. Improper validation of PNG chunk length during PNG file processing in AMI firmware leads to OOB read.
Image preview
Potential Impact
This vulnerability will not lead to exploitation, however, it may lead to unexpected behaviour during PNG file processing.
Image preview
Vulnerability Information
- BINARLY internal vulnerability identifier: BRLY-LOGOFAIL-2023-014
- CVSS v3.1: 3.2 Low AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
Image preview
See if you are impacted now with our Firmware Vulnerability Scanner
Find Vulnerabilities, Generate SBOMs & CBOMs