9

CVE-2019-6322

HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is enabled by default.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ Z4 G4 Workstation Firmware Version < 1.70
   Hp ≫ Z4 G4 Workstation Version -
Hp ≫ Z4 G4 Core-x Workstation Firmware Version < 1.70
   Hp ≫ Z4 G4 Core-x Workstation Version -
Hp ≫ Z6 G4 Workstation Firmware Version < 1.71
   Hp ≫ Z6 G4 Workstation Version -
Hp ≫ Z8 G4 Workstation Firmware Version < 1.71
   Hp ≫ Z8 G4 Workstation Version -
Hp ≫ Z4 G4 Workstation Firmware SwPlatform linux Version < 1.70
   Hp ≫ Z4 G4 Workstation Version -
Hp ≫ Z4 G4 Core-x Workstation Firmware SwPlatform linux Version < 1.70
   Hp ≫ Z4 G4 Core-x Workstation Version -
Hp ≫ Z6 G4 Workstation Firmware SwPlatform linux Version < 1.71
   Hp ≫ Z6 G4 Workstation Version -
Hp ≫ Z8 G4 Workstation Firmware SwPlatform linux Version < 1.71
   Hp ≫ Z8 G4 Workstation Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.24% 0.652
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 0.9 5.9
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-667 Improper Locking

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

https://support.hp.com/us-en/document/c06318199
Patch
Vendor Advisory