Skip to main content

Milestone Security Advisory

Husky IVO — LogoFAIL vulnerability

Last Updated: 1 minute read
LanguageEnglish

LogoFAIL vulnerabilities are tracked under the following designations: CVE-2023-5058, CVE-2023-39538, CVE-2023-39539, and CVE-2023-40238. (The list is however currently incomplete and may be updated later.) 

For Husky IVO series, we have received the following vendor statements: 

Client Products: 

Client products are not impacted by the UEFI image parser vulnerabilities reported by Binarly Research. Dell client products apply data protection mechanisms (such as Intel Boot Guard) that prevent exploitation of these vulnerabilities.  

 PowerEdge Servers:

PowerEdge Servers are not impacted by the UEFI image parser vulnerabilities reported by Binarly Research. PowerEdge BIOS does not use firmware affected by the disclosed vulnerabilities.

 Additional information:

"Finding LogoFAIL: The Dangers of Image Parsing During System Boot" (06-Dec-2023, Binarly REsearch)

Article Number

000003881