VulnerabilityModified
CVE-2023-26300
A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege.
HIGH 7.8EPSS 0.18%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege. HP is releasing firmware updates to mitigate the potential vulnerability.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Affected
- hp/desktop pro a 300 g3 firmware · hp/desktop pro a g3 firmware · hp/desktop pro a g3 microtower firmware · hp/zhan 66 pro a g1 r microtower firmware · hp/t638 thin client firmware · hp/stream 11 pro g5 firmware · hp/240 g10 firmware · hp/240 g6 firmware · hp/240 g7 firmware · hp/240 g9 firmware · hp/245 g10 firmware · hp/245 g7 firmware · hp/245 g8 firmware · hp/245 g9 firmware · hp/245 firmware · hp/246 g6 firmware · hp/246 g7 firmware · hp/247 g8 firmware · hp/250 g10 firmware · hp/250 g6 firmware · +40 more
- Source
- hp-security-alert@hp.com
References
- https://support.hp.com/us-en/document/ish_9461800-9461828-16Patch, Vendor Advisory
- https://support.hp.com/us-en/document/ish_9461800-9461828-16Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.