Lucene search

K
hpHP Product Security Response TeamHPSBHF03799
HistoryJul 21, 2022 - 12:00 a.m.

HP PC UEFI Secure Boot Database Update July 2022

2022-07-2100:00:00
HP Product Security Response Team
support.hp.com
60
hp
uefi
secure boot
update
vulnerabilities
standalone utility
security advisory

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS

0.002

Percentile

58.6%

Potential vulnerabilities have been identified in certain UEFI applications signed by HP which may allow local arbitrary code execution. HP is providing a standalone Secure Boot Update Utility (SBUU) for identified HP PC products to update the secure boot database so that these vulnerable UEFI applications will not execute.

HP has identified affected platforms and corresponding SoftPaqs with minimum versions that mitigate the potential vulnerabilities. See the affected platforms listed below.

Affected configurations

Vulners
Node
hphp_348_g4Range<1.0.5.1
OR
hphp_elite_x2_1011_g1Range<1.0.5.1
OR
hphp_elite_x2_1012_g1Range<1.0.5.1
OR
hphp_elite_x2_1012_g1_tabletRange<1.0.5.1
OR
hphp_elite_x2_1012_g1_tablet_with_travel_keyboardRange<1.0.5.1
OR
hphp_elite_x2_1012_g2Range<1.0.5.1
OR
hphp_elitebook_1030_g1Range<1.0.5.1
OR
hpelitebook_1040_g3_firmwareRange<1.0.5.1
OR
hphp_elitebook_1040_g4Range<1.0.5.1
OR
hphp_elitebook_720_g1Range<1.0.5.1
OR
hpelitebook_725_g3_firmwareRange<1.0.5.1
OR
hphp_elitebook_725_g4Range<1.0.5.1
OR
hpelitebook_745_g3_firmwareRange<1.0.5.1
OR
hphp_elitebook_745_g4Range<1.0.5.1
OR
hpelitebook_755_g3_firmwareRange<1.0.5.1
OR
hphp_elitebook_755_g4Range<1.0.5.1
OR
hpelitebook_820_g3_firmwareRange<1.0.5.1
OR
hphp_elitebook_820_g4Range<1.0.5.1
OR
hpelitebook_828_g3_firmwareRange<1.0.5.1
OR
hphp_elitebook_828_g4Range<1.0.5.1
OR
hpelitebook_840_g3_firmwareRange<1.0.5.1
OR
hphp_elitebook_840_g4Range<1.0.5.1
OR
hpelitebook_848_g3_firmwareRange<1.0.5.1
OR
hphp_elitebook_848_g4Range<1.0.5.1
OR
hpelitebook_850_g3_firmwareRange<1.0.5.1
OR
hphp_elitebook_850_g4Range<1.0.5.1
OR
hphp_elitebook_folio_g1Range<1.0.5.1
OR
hpelitebook_revolve_810_g3_firmwareRange<1.0.5.1
OR
hphp_elitebook_x360_1020_g2Range<1.0.5.1
OR
hphp_elitebook_x360_1030_g2Range<1.0.5.1
OR
hphp_pro_x2_612_g1Range<1.0.5.1
OR
hphp_pro_x2_612_g1Range<1.0.5.1
OR
hphp_pro_x2_612_g2Range<1.0.5.1
OR
hphp_probook_11_ee_g2Range<1.0.5.1
OR
hphp_probook_430_g4Range<1.0.5.1
OR
hphp_probook_440_g4Range<1.0.5.1
OR
hpprobook_446_g3_firmwareRange<1.0.5.1
OR
hpprobook_450_g3_firmwareRange<1.0.5.1
OR
hphp_probook_450_g4Range<1.0.5.1
OR
hphp_probook_455_g4Range<1.0.5.1
OR
hpprobook_470_g3_firmwareRange<1.0.5.1
OR
hphp_probook_470_g4Range<1.0.5.1
OR
hphp_probook_640_g2Range<1.0.5.1
OR
hpprobook_640_g3_firmwareRange<1.0.5.1
OR
hphp_probook_645_g2Range<1.0.5.1
OR
hpprobook_645_g3_firmwareRange<1.0.5.1
OR
hphp_probook_650_g2Range<1.0.5.1
OR
hphp_probook_650_g2Range<1.0.5.1
OR
hpprobook_650_g3_firmwareRange<1.0.5.1
OR
hpprobook_650_g3_firmwareRange<1.0.5.1
OR
hphp_probook_655_g2Range<1.0.5.1
OR
hpprobook_655_g3_firmwareRange<1.0.5.1
OR
hphp_probook_x360_11_g1_eeRange<1.0.5.1
OR
hphp_probook_x360_11_g2_eeRange<1.0.5.1
OR
hphp_zbook_14u_g4Range<1.0.5.1
OR
hpzbook_15_g2Range<1.0.5.1
OR
hpzbook_15_g3_firmwareRange<1.0.5.1
OR
hphp_zbook_15_g4Range<1.0.5.1
OR
hpzbook_15u_g3_firmwareRange<1.0.5.1
OR
hphp_zbook_15u_g4Range<1.0.5.1
OR
hpzbook_17_g2Range<1.0.5.1
OR
hpzbook_17_g3_firmwareRange<1.0.5.1
OR
hphp_zbook_17_g4Range<1.0.5.1
OR
hpzbook_studio_g3_firmwareRange<1.0.5.1
OR
hphp_zbook_studio_g4Range<1.0.5.1
OR
hphp_zbook_x2_g4Range<1.0.5.1
OR
hphp_260_g2_desktop_miniRange<1.0.5.1
OR
hphp_elite_sliceRange<1.0.5.1
OR
hpelite_slice_for_meeting_rooms_firmwareRange<1.0.5.1
OR
hpelite_slice_g2_-_audio_ready_with_zoom_rooms_firmwareRange<1.0.5.1
OR
hpelite_slice_g2_-_partner_ready_with_microsoft_teams_rooms_firmwareRange<1.0.5.1
OR
hpelite_slice_g2_with_microsoft_teams_rooms_firmwareRange<1.0.5.1
OR
hphp_elite_slice_g2_with_intel_uniteRange<1.0.5.1
OR
hpelite_slice_g2_with_zoom_rooms_firmwareRange<1.0.5.1
OR
hpelitedesk_705_g3_microtower_pc_firmwareRange<1.0.5.1
OR
hpelitedesk_705_g3_small_form_factor_pc_firmwareRange<1.0.5.1
OR
hphp_elitedesk_705_g4_desktop_mini_pcRange<1.0.5.1
OR
hphp_elitedesk_705_g4_microtower_pcRange<1.0.5.1
OR
hphp_elitedesk_705_g4_small_form_factor_pcRange<1.0.5.1
OR
hpelitedesk_705_g4_workstation_edition_firmwareRange<1.0.5.1
OR
hphp_elitedesk_800_35w_g2_desktop_mini_pcRange<1.0.5.1
OR
hpelitedesk_800_35w_g3_desktop_mini_pc_firmwareRange<1.0.5.1
OR
hphp_elitedesk_800_35w_g4_desktop_mini_pcRange<1.0.5.1
OR
hphp_elitedesk_800_65w_g2_desktop_mini_pcRange<1.0.5.1
OR
hpelitedesk_800_65w_g3_desktop_mini_pc_firmwareRange<1.0.5.1
OR
hphp_elitedesk_800_65w_g4_desktop_mini_pcRange<1.0.5.1
OR
hphp_elitedesk_800_95w_g4_desktop_mini_pcRange<1.0.5.1
OR
hphp_elitedesk_800_g2_small_form_factor_pcRange<1.0.5.1
OR
hphp_elitedesk_800_g2_tower_pcRange<1.0.5.1
OR
hpelitedesk_800_g3_small_form_factor_pc_firmwareRange<1.0.5.1
OR
hpelitedesk_800_g3_tower_pc_firmwareRange<1.0.5.1
OR
hphp_elitedesk_800_g4_small_form_factor_pcRange<1.0.5.1
OR
hphp_elitedesk_800_g4_tower_pcRange<1.0.5.1
OR
hpelitedesk_800_g4_workstation_edition_firmwareRange<1.0.5.1
OR
hphp_elitedesk_800_g5_desktop_mini_pcRange<1.0.5.1
OR
hphp_elitedesk_800_g5_small_form_factor_pcRange<1.0.5.1
OR
hphp_elitedesk_800_g5_tower_pcRange<1.0.5.1
OR
hphp_elitedesk_800_g6_desktop_mini_pcRange<1.0.5.1
OR
hphp_elitedesk_880_g2_tower_pcRange<1.0.5.1
OR
hpelitedesk_880_g3_tower_pc_firmwareRange<1.0.5.1
OR
hphp_elitedesk_880_g4_tower_pcRange<1.0.5.1
OR
hphp_elitedesk_880_g5_tower_pcRange<1.0.5.1
OR
hphp_eliteone_1000_g1_23.8-in_all-in-oneRange<1.0.5.1
OR
hphp_eliteone_1000_g1_23.8-in_touch_all-in-oneRange<1.0.5.1
OR
hphp_eliteone_1000_g1_27-in_4k_uhd_all-in-oneRange<1.0.5.1
OR
hphp_eliteone_1000_g1_34-in_curved_all-in-oneRange<1.0.5.1
OR
hphp_eliteone_1000_g2_23.8-in_all-in-oneRange<1.0.5.1
OR
hpeliteone_1000_g2_23.8-in_touch_all-in-one_business_pc_firmwareRange<1.0.5.1
OR
hphp_eliteone_1000_g2_27-in_4k_uhd_all-in-oneRange<1.0.5.1
OR
hphp_eliteone_1000_g2_34-in_curved_all-in-oneRange<1.0.5.1
OR
hphp_eliteone_705_g2_all-in-one_pc_touchRange<1.0.5.1
OR
hphp_eliteone_800_g2_23-inch_non-touch_all-in-one_pcRange<1.0.5.1
OR
hphp_eliteone_800_g2_23-inch_non-touch_all-in-one_pcRange<1.0.5.1
OR
hphp_eliteone_800_g2_23-inch_touch_all-in-one_pcRange<1.0.5.1
OR
hphp_eliteone_800_g2_23-inch_touch_all-in-one_pcRange<1.0.5.1
OR
hpeliteone_800_g3_23.8_non-touch_healthcare_edition_all-in-one_business_pc_firmwareRange<1.0.5.1
OR
hpeliteone_800_g3_23.8-inch_non-touch_all-in-one_pc_firmwareRange<1.0.5.1
OR
hpeliteone_800_g3_23.8-inch_non-touch_gpu_all-in-one_pc_firmwareRange<1.0.5.1
OR
hpeliteone_800_g3_23.8-inch_touch_all-in-one_pc_firmwareRange<1.0.5.1
OR
hpeliteone_800_g3_23.8-inch_touch_gpu_all-in-one_pc_firmwareRange<1.0.5.1
OR
hpeliteone_800_g4_23.8-in_healthcare_edition_all-in-one_business_pc_firmwareRange<1.0.5.1
OR
hphp_eliteone_800_g4_23.8-inch_non-touch_all-in-one_pcRange<1.0.5.1
OR
hphp_eliteone_800_g4_23.8-inch_non-touch_gpu_all-in-one_pcRange<1.0.5.1
OR
hphp_eliteone_800_g4_23.8-inch_touch_all-in-one_pcRange<1.0.5.1
OR
hphp_eliteone_800_g4_23.8-inch_touch_gpu_all-in-one_pcRange<1.0.5.1
OR
hpeliteone_800_g5_23.8-in_healthcare_edition_all-in-one_firmwareRange<1.0.5.1
OR
hphp_eliteone_800_g5_23.8-inch_all-in-oneRange<1.0.5.1
OR
hphp_prodesk_400_g2_desktop_mini_pcRange<1.0.5.1
OR
hpprodesk_400_g3_desktop_mini_pc_firmwareRange<1.0.5.1
OR
hphp_prodesk_400_g4_desktop_mini_pcRange<1.0.5.1
OR
hphp_prodesk_400_g4_microtower_pcRange<1.0.5.1
OR
hphp_prodesk_400_g4_small_form_factor_pcRange<1.0.5.1
OR
hphp_prodesk_400_g5_desktop_mini_pcRange<1.0.5.1
OR
hphp_prodesk_400_g5_microtower_pcRange<1.0.5.1
OR
hphp_prodesk_400_g5_small_form_factor_pcRange<1.0.5.1
OR
hphp_prodesk_400_g6_microtower_pcRange<1.0.5.1
OR
hphp_prodesk_400_g6_small_form_factor_pcRange<1.0.5.1
OR
hphp_prodesk_405_g4_small_form_factor_pcRange<1.0.5.1
OR
hphp_prodesk_480_g4_microtower_pcRange<1.0.5.1
OR
hphp_prodesk_480_g5_microtower_pcRange<1.0.5.1
OR
hphp_prodesk_480_g6_microtower_pcRange<1.0.5.1
OR
hphp_prodesk_600_g2_desktop_mini_pcRange<1.0.5.1
OR
hphp_prodesk_600_g2_microtower_pcRange<1.0.5.1
OR
hphp_prodesk_600_g2_small_form_factor_pcRange<1.0.5.1
OR
hpprodesk_600_g3_desktop_mini_pc_firmwareRange<1.0.5.1
OR
hpprodesk_600_g3_microtower_pc_firmwareRange<1.0.5.1
OR
hpprodesk_600_g3_small_form_factor_pc_firmwareRange<1.0.5.1
OR
hphp_prodesk_600_g4_desktop_mini_pcRange<1.0.5.1
OR
hphp_prodesk_600_g4_microtower_pcRange<1.0.5.1
OR
hphp_prodesk_600_g4_microtower_pc_\(with_pci_slot\)Range<1.0.5.1
OR
hphp_prodesk_600_g4_small_form_factor_pcRange<1.0.5.1
OR
hphp_prodesk_600_g5_desktop_mini_pcRange<1.0.5.1
OR
hphp_prodesk_600_g5_microtower_pcRange<1.0.5.1
OR
hphp_prodesk_600_g5_microtower_pc_\(with_pci_slot\)Range<1.0.5.1
OR
hphp_prodesk_600_g5_small_form_factor_pcRange<1.0.5.1
OR
hphp_prodesk_680_g2_microtower_pcRange<1.0.5.1
OR
hpprodesk_680_g3_microtower_pc_firmwareRange<1.0.5.1
OR
hphp_prodesk_680_g4_microtower_pcRange<1.0.5.1
OR
hphp_prodesk_680_g4_microtower_pc_\(with_pci_slot\)Range<1.0.5.1
OR
hphp_proone_400_g2_20-inch_non-touch_all-in-one_pcRange<1.0.5.1
OR
hphp_proone_400_g2_20-inch_touch_all-in-one_pcRange<1.0.5.1
OR
hpproone_400_g3_20-inch_non-touch_all-in-one_pc_firmwareRange<1.0.5.1
OR
hpproone_400_g3_20-inch_touch_all-in-one_pc_firmwareRange<1.0.5.1
OR
hphp_proone_400_g4_20-inch_non-touch_all-in-oneRange<1.0.5.1
OR
hpproone_400_g4_23.8-inch_non-touch_all-in-one_business_pc_firmwareRange<1.0.5.1
OR
hpproone_400_g5_20-inch_all-in-one_business_pc_firmwareRange<1.0.5.1
OR
hphp_proone_400_g5_23.8-inch_all-in-oneRange<1.0.5.1
OR
hphp_proone_440_g4_23.8-inch_non-touch_all-in-oneRange<1.0.5.1
OR
hpproone_440_g5_23.8-in_all-in-one_business_pc_firmwareRange<1.0.5.1
OR
hpproone_480_g3_20-inch_non-touch_all-in_one_pc_firmwareRange<1.0.5.1
OR
hphp_proone_600_g2_21.5-inch_non-touch_all-in-one_pcRange<1.0.5.1
OR
hphp_proone_600_g2_21.5-inch_touch_all-in-one_pcRange<1.0.5.1
OR
hpproone_600_g3_21.5-inch_non-touch_all-in-one_firmwareRange<1.0.5.1
OR
hpproone_600_g4_21.5-inch_touch_all-in-one_business_pc_firmwareRange<1.0.5.1
OR
hphp_proone_600_g5_21.5-in_all-in-oneRange<1.0.5.1
OR
hphp_z1_entry_tower_g5Range<1.0.5.1
OR
hphp_engage_flex_pro_retail_systemRange<1.0.5.1
OR
hpengage_flex_pro-c_retail_system_firmwareRange<1.0.5.1
OR
hphp_engage_one_all-in-one_systemRange<1.0.5.1
OR
hphp_mp9_g2_retail_systemRange<1.0.5.1
OR
hphp_mp9_g4_retail_systemRange<1.0.5.1
OR
hphp_rp2_retail_system_model_2000Range<1.0.5.1
OR
hphp_rp2_retail_system_model_2020Range<1.0.5.1
OR
hphp_rp5_retail_system_model_5810Range<1.0.5.1
OR
hphp_rp7_retail_system_model_7100Range<1.0.5.1
OR
hphp_rp7_retail_system_model_7800Range<1.0.5.1
OR
hphp_rp9_g1_retail_systemRange<1.0.5.1
OR
hphp_z2_small_form_factor_g4_workstationRange<1.0.5.1
OR
hphp_z2_small_form_factor_g4_workstationRange<1.00
OR
hphp_z2_tower_g4_workstationRange<1.0.5.1
OR
hphp_z2_tower_g4_workstationRange<1.00
OR
hphp_z2_mini_g4_workstationRange<1.0.5.1
OR
hphp_z2_mini_g4_workstationRange<1.00
OR
hphp_z8_g4_workstationRange<1.0.5.1
OR
hphp_z8_g4_workstationRange<1.00
OR
hphp_z6_g4_workstationRange<1.0.5.1
OR
hphp_z6_g4_workstationRange<1.00
OR
hphp_z4_g4_workstation_\(xeon_w\)Range<1.0.5.1
OR
hphp_z4_g4_workstation_\(xeon_w\)Range<1.00
OR
hphp_z4_g4_workstation_\(core-x\)Range<1.0.5.1
OR
hphp_z4_g4_workstation_\(core-x\)Range<1.00
OR
hphp_z240_small_form_factor_workstationRange<1.0.5.1
OR
hphp_z240_small_form_factor_workstationRange<1.00
OR
hphp_z240_tower_workstationRange<1.0.5.1
OR
hphp_z240_tower_workstationRange<1.00
OR
hphp_z238_microtower_workstationRange<1.0.5.1
OR
hphp_z238_microtower_workstationRange<1.00
OR
hpz2_mini_g3_workstation_firmwareRange<1.0.5.1
OR
hpz2_mini_g3_workstation_firmwareRange<1.00
OR
hphp_z840_workstationRange<1.0.5.1
OR
hphp_z840_workstationRange<1.00
OR
hphp_z640_workstationRange<1.0.5.1
OR
hphp_z640_workstationRange<1.00
OR
hphp_z440_workstationRange<1.0.5.1
OR
hphp_z440_workstationRange<1.00
OR
hpz1_all-in-one_g3_workstation_firmwareRange<1.0.5.1
OR
hpz1_all-in-one_g3_workstation_firmwareRange<1.00
OR
hphp_all-in-one_20-cxxx_\(rom_family_ssid_81bb\)Range<1.0.4.5
OR
hphp_all-in-one_22-bxxx_\(rom_family_ssid_81bb\)Range<1.0.4.5
OR
hphp_all-in-one_24-exxx_\(rom_family_ssid_81bb\)Range<1.0.4.5
OR
hphp_all-in-one_24-gxxx_\(rom_family_ssid_81bb\)Range<1.0.4.5
OR
hphp_pavilion_wave_600-axxx_\(rom_family_ssid_82fd\)Range<1.0.4.5
VendorProductVersionCPE
hphp_348_g4*cpe:2.3:a:hp:hp_348_g4:*:*:*:*:*:*:*:*
hphp_elite_x2_1011_g1*cpe:2.3:a:hp:hp_elite_x2_1011_g1:*:*:*:*:*:*:*:*
hphp_elite_x2_1012_g1*cpe:2.3:a:hp:hp_elite_x2_1012_g1:*:*:*:*:*:*:*:*
hphp_elite_x2_1012_g1_tablet*cpe:2.3:a:hp:hp_elite_x2_1012_g1_tablet:*:*:*:*:*:*:*:*
hphp_elite_x2_1012_g1_tablet_with_travel_keyboard*cpe:2.3:a:hp:hp_elite_x2_1012_g1_tablet_with_travel_keyboard:*:*:*:*:*:*:*:*
hphp_elite_x2_1012_g2*cpe:2.3:a:hp:hp_elite_x2_1012_g2:*:*:*:*:*:*:*:*
hphp_elitebook_1030_g1*cpe:2.3:a:hp:hp_elitebook_1030_g1:*:*:*:*:*:*:*:*
hpelitebook_1040_g3_firmware*cpe:2.3:o:hp:elitebook_1040_g3_firmware:*:*:*:*:*:*:*:*
hphp_elitebook_1040_g4*cpe:2.3:a:hp:hp_elitebook_1040_g4:*:*:*:*:*:*:*:*
hphp_elitebook_720_g1*cpe:2.3:a:hp:hp_elitebook_720_g1:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 2021

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS

0.002

Percentile

58.6%