Lucene search

K
cve[email protected]CVE-2021-3661
HistoryDec 12, 2022 - 1:15 p.m.

CVE-2021-3661

2022-12-1213:15:11
web.nvd.nist.gov
32
hp
workstation
bios
uefi
firmware
vulnerability
cve-2021-3661
arbitrary code execution
hp
nvd

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.6%

A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.

Affected configurations

NVD
Node
hpz1_all-in-one_g3Match-
AND
hpz1_all-in-one_g3_firmwareMatch01.31
Node
hpz2_mini_g3Match-
AND
hpz2_mini_g3_firmwareMatch01.83
Node
hpz2_mini_g4_firmwareMatch01.08.01
AND
hpz2_mini_g4Match-
Node
hpz2_mini_g5_firmwareMatch01.03.00_rev_a
AND
hpz2_mini_g5Match-
Node
hpz2_small_form_factor_g4_firmwareMatch01.08.01
AND
hpz2_small_form_factor_g4Match-
Node
hpz2_small_form_factor_g5_firmwareMatch01.03.00_rev_a
AND
hpz2_small_form_factor_g5Match-
Node
hpz2_small_form_factor_g8_firmwareMatch01.03.00_rev_a
AND
hpz2_small_form_factor_g8Match-
Node
hpz2_tower_g4_firmwareMatch01.08.01
AND
hpz2_tower_g4Match-
Node
hpz2_tower_g5_firmwareMatch01.03.00_rev_a
AND
hpz2_tower_g5Match-
Node
hpz2_tower_g8_firmwareMatch01.03.00_rev_a
AND
hpz2_tower_g8Match-
Node
hpz238_microtower_firmwareMatch01.83
AND
hpz238_microtowerMatch-
Node
hpz240_small_form_factor_firmwareMatch01.83
AND
hpz240_small_form_factorMatch-
Node
hpz240_tower_firmwareMatch01.83
AND
hpz240_towerMatch-
Node
hpz4_g4_firmwareMatch02.75
AND
hpz4_g4Match-
Node
hpz440_firmwareMatch2.58
AND
hpz440Match-
Node
hpz6_g4_firmwareMatch02.75
AND
hpz6_g4Match-
Node
hpz640_firmwareMatch2.58
AND
hpz640Match-
Node
hpz8_g4_firmwareMatch02.75
AND
hpz8_g4Match-
Node
hpz840_firmwareMatch2.58
AND
hpz840Match-
Node
hpzcentral_4r_firmwareMatch01.18
AND
hpzcentral_4rMatch-

CNA Affected

[
  {
    "versions": [
      {
        "version": "See HP Security Bulletin reference for affected versions.",
        "status": "affected"
      }
    ],
    "product": "HP Workstation BIOS",
    "vendor": "HP Inc."
  }
]

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.6%

Related for CVE-2021-3661