CVE-2023-40238 is a LogoFAIL vulnerability in Insyde InsydeH2O firmware, specifically affecting BmpDecoderDxe in certain Lenovo devices and other products from Fujitsu and Insyde. This medium-severity vulnerability (CVSS 5.5) stems from an integer signedness error during image parsing of crafted BMP logo files, allowing data to be copied to specific memory addresses during the UEFI DXE phase, potentially leading to a denial of service. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, including reports of its use in UEFI malware like BootKitty.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.35.0CPE matchmatch criteria | cpe:2.3:o:fujitsu:esprimo_d556\/2_firmware:*:*:*:*:*:*:*:* | ||
< 1.31.0CPE matchmatch criteria | cpe:2.3:o:fujitsu:esprimo_d6011_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.0CPE matchmatch criteria | cpe:2.3:o:fujitsu:esprimo_d6012_firmware:*:*:*:*:*:*:*:* | ||
< 1.64.0CPE matchmatch criteria | cpe:2.3:o:fujitsu:esprimo_d7010_firmware:*:*:*:*:*:*:*:* | ||
< 1.64.0CPE matchmatch criteria | cpe:2.3:o:fujitsu:esprimo_d7010\/8_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.