They did patch the reported vulnerabilities in updates. What chipsec reports as warnings are not necessarily exploitable. i.e., They didn't patch them to the extent of getting all green ticks in chipsec, but it does not automatically imply exploitable.
You would have to dump an image of your bios firmware using chipsec to confirm for yourself. https://github.com/chipsec/chipsec