![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-42442 – Runtime Service Access outside SMRAM
https://notcve.org/view.php?id=CVE-2024-42442
12 Nov 2024 — APTIOV contains a vulnerability in the BIOS where a user or attacker may cause an improper restriction of operations within the bounds of a memory buffer over the network. A successful exploitation of this vulnerability may lead to code execution outside of the intended System Management Mode. • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/2024/AMI-SA-2024004.pdf • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-33657 – Smm Callout in SmmComputrace Module
https://notcve.org/view.php?id=CVE-2024-33657
21 Aug 2024 — This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak information from SMRAM to kernel space, potentially leading to denial-of-service attacks. • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/2024/AMI-SA-2024003.pdf • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-33656 – Memory Leak in SmmComuptrace Module
https://notcve.org/view.php?id=CVE-2024-33656
21 Aug 2024 — The DXE module SmmComputrace contains a vulnerability that allows local attackers to leak stack or global memory. This could lead to privilege escalation, arbitrary code execution, and bypassing OS security mechanisms • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/2024/AMI-SA-2024003.pdf • CWE-269: Improper Privilege Management •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-39538 – Failure when uploading a Logo image file
https://notcve.org/view.php?id=CVE-2023-39538
06 Dec 2023 — AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. AMI AptioV contiene una vulnerabilidad en BIOS donde un usuario puede provocar una carga sin restricciones de un archivo de logotipo BMP con un tipo peligroso mediante acceso local. Una explotación exitosa de esta vulnerabilidad puede provocar una pérd... • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023009.pdf • CWE-20: Improper Input Validation CWE-434: Unrestricted Upload of File with Dangerous Type •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-39539 – Failure when uploading a Logo image file
https://notcve.org/view.php?id=CVE-2023-39539
06 Dec 2023 — AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. AMI AptioV contiene una vulnerabilidad en BIOS donde un usuario puede provocar una carga sin restricciones de un archivo de logotipo PNG con un tipo peligroso mediante acceso local. Una explotación exitosa de esta vulnerabilidad puede provocar una pérd... • https://github.com/AdamWen230/CVE-2023-39539-PoC • CWE-20: Improper Input Validation CWE-434: Unrestricted Upload of File with Dangerous Type •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-39537 – Improper input validation in BIOS TCG2
https://notcve.org/view.php?id=CVE-2023-39537
14 Nov 2023 — AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity and availability. AMI AptioV contiene una vulnerabilidad en el BIOS donde un atacante puede utilizar una validación de entrada incorrecta a través de la red local. Una explotación exitosa de esta vulnerabilidad puede provocar una pérdida de confidencialidad, integridad y disponibilidad. • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023008.pdf • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-39536 – Improper input validation in BIOS OFBD
https://notcve.org/view.php?id=CVE-2023-39536
14 Nov 2023 — AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity and availability. AMI AptioV contiene una vulnerabilidad en el BIOS donde un atacante puede utilizar una validación de entrada incorrecta a través de la red local. Una explotación exitosa de esta vulnerabilidad puede provocar una pérdida de confidencialidad, integridad y disponibilidad. • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023008.pdf • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-39535 – Improper input validation in BIOS
https://notcve.org/view.php?id=CVE-2023-39535
14 Nov 2023 — AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity and availability. AMI AptioV contiene una vulnerabilidad en el BIOS donde un atacante puede utilizar una validación de entrada incorrecta a través de la red local. Una explotación exitosa de esta vulnerabilidad puede provocar una pérdida de confidencialidad, integridad y disponibilidad. • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023008.pdf • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-34470 – Improper access control
https://notcve.org/view.php?id=CVE-2023-34470
12 Sep 2023 — AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the local network. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity and availability. AMI AptioV contiene una vulnerabilidad en el BIOS donde un atacante puede utilizar un control de acceso inadecuado a través de la red local. Una explotación exitosa de esta vulnerabilidad puede provocar la pérdida de confidencialidad, integridad y disponibilidad. • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023007.pdf • CWE-284: Improper Access Control •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-34469 – Cold Rest Vulnerabiltiy
https://notcve.org/view.php?id=CVE-2023-34469
12 Sep 2023 — AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the physical network. A successful exploit of this vulnerability may lead to a loss of confidentiality. AMI AptioV contiene una vulnerabilidad en el BIOS donde un atacante puede utilizar un control de acceso inadecuado a través de la red física. Una explotación exitosa de esta vulnerabilidad puede provocar la pérdida de confidencialidad. • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023007.pdf • CWE-284: Improper Access Control •