VulnerabilityModified
CVE-2021-3808
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution.
HIGH 7.8EPSS 0.24%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.24% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- hp/elite dragonfly firmware · hp/elite x2 1012 g2 firmware · hp/elite x2 1013 g3 firmware · hp/elite x2 g4 firmware · hp/elitebook 1040 g4 firmware · hp/elitebook 1050 g1 firmware · hp/elitebook 725 g4 firmware · hp/elitebook 735 g5 firmware · hp/elitebook 735 g6 firmware · hp/elitebook 745 g4 firmware · hp/elitebook 745 g5 firmware · hp/elitebook 745 g6 firmware · hp/elitebook 755 g4 firmware · hp/elitebook 755 g5 firmware · hp/elitebook 820 g4 firmware · hp/elitebook 828 g4 firmware · hp/elitebook 830 g5 firmware · hp/elitebook 830 g6 firmware · hp/elitebook 836 g5 firmware · hp/elitebook 836 g6 firmware · +40 more
- Source
- hp-security-alert@hp.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.