๐Ÿ” CVE Alert

CVE-2023-39538

HIGH 7.5

Failure when uploading a Logo image file

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.ย 

CWE CWE-20 CWE-434
Vendor ami
Product aptiov
Published Dec 6, 2023
Last Updated Feb 25, 2026
Stay Ahead of the Next One

Get instant alerts for ami aptiov

Be the first to know when new high vulnerabilities affecting ami aptiov are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

AMI / AptioV
BKS_5.0 < BKS_5.34

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
9443417.fs1.hubspotusercontent-na1.net: https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023009.pdf security.netapp.com: https://security.netapp.com/advisory/ntap-20240105-0003/

Credits

Binarly efiXplorer Team