Security News > 2024 > December > BootKitty UEFI malware exploits LogoFAIL to infect Linux systems

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-12-07 CVE-2023-40238 Cleartext Storage of Sensitive Information vulnerability in Insyde Insydeh2O
A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.47, 5.4 before 05.45.47, 5.5 before 05.53.47, and 5.6 before 05.60.47 for certain Lenovo devices.
local
low complexity
insyde CWE-312
5.5

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Linux 11 64 2397 1510 67 4038