SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-26299

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution.

HIGH 7.0EPSS 0.13%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.

CVSS 3.1
7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.13% probability · 3th percentile
CISA KEV
Not listed
Weakness
CWE-367
Affected
hp/260 g4 desktop mini firmware · hp/t430 firmware · hp/t628 firmware · hp/240 g10 firmware · hp/245 g6 firmware · hp/245 g7 firmware · hp/245 g8 firmware · hp/247 g8 firmware · hp/250 g10 firmware · hp/255 g10 firmware · hp/349 g7 firmware · hp/470 g10 firmware · hp/470 g9 firmware · hp/zhan 99 g2 firmware · hp/zhan 99 g4 firmware · hp/vr backpack g2 firmware · hp/200 g3 firmware · hp/200 g4 22 all-in-one firmware · hp/200 pro g4 22 all-in-one firmware · hp/205 g4 22 all-in-one firmware · +39 more
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.