9

CVE-2019-6322

HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is enabled by default.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpZ4 G4 Workstation Firmware Version < 1.70
   HpZ4 G4 Workstation Version-
HpZ4 G4 Core-x Workstation Firmware Version < 1.70
   HpZ4 G4 Core-x Workstation Version-
HpZ6 G4 Workstation Firmware Version < 1.71
   HpZ6 G4 Workstation Version-
HpZ8 G4 Workstation Firmware Version < 1.71
   HpZ8 G4 Workstation Version-
HpZ4 G4 Workstation Firmware SwPlatformlinux Version < 1.70
   HpZ4 G4 Workstation Version-
HpZ4 G4 Core-x Workstation Firmware SwPlatformlinux Version < 1.70
   HpZ4 G4 Core-x Workstation Version-
HpZ6 G4 Workstation Firmware SwPlatformlinux Version < 1.71
   HpZ6 G4 Workstation Version-
HpZ8 G4 Workstation Firmware SwPlatformlinux Version < 1.71
   HpZ8 G4 Workstation Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.541
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-667 Improper Locking

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.