8.4

CVE-2021-3661

A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ Z1 All-in-one G3 Firmware Version 01.31
   Hp ≫ Z1 All-in-one G3 Version -
Hp ≫ Z2 Mini G3 Firmware Version 01.83
   Hp ≫ Z2 Mini G3 Version -
Hp ≫ Z2 Mini G4 Firmware Version 01.08.01
   Hp ≫ Z2 Mini G4 Version -
Hp ≫ Z2 Mini G5 Firmware Version 01.03.00_rev_a
   Hp ≫ Z2 Mini G5 Version -
Hp ≫ Z2 Small Form Factor G4 Firmware Version 01.08.01
   Hp ≫ Z2 Small Form Factor G4 Version -
Hp ≫ Z2 Small Form Factor G5 Firmware Version 01.03.00_rev_a
   Hp ≫ Z2 Small Form Factor G5 Version -
Hp ≫ Z2 Small Form Factor G8 Firmware Version 01.03.00_rev_a
   Hp ≫ Z2 Small Form Factor G8 Version -
Hp ≫ Z2 Tower G4 Firmware Version 01.08.01
   Hp ≫ Z2 Tower G4 Version -
Hp ≫ Z2 Tower G5 Firmware Version 01.03.00_rev_a
   Hp ≫ Z2 Tower G5 Version -
Hp ≫ Z2 Tower G8 Firmware Version 01.03.00_rev_a
   Hp ≫ Z2 Tower G8 Version -
Hp ≫ Z238 Microtower Firmware Version 01.83
   Hp ≫ Z238 Microtower Version -
Hp ≫ Z240 Small Form Factor Firmware Version 01.83
   Hp ≫ Z240 Small Form Factor Version -
Hp ≫ Z240 Tower Firmware Version 01.83
   Hp ≫ Z240 Tower Version -
Hp ≫ Z4 G4 Firmware Version 02.75
   Hp ≫ Z4 G4 Version -
Hp ≫ Z440 Firmware Version 2.58
   Hp ≫ Z440 Version -
Hp ≫ Z6 G4 Firmware Version 02.75
   Hp ≫ Z6 G4 Version -
Hp ≫ Z640 Firmware Version 2.58
   Hp ≫ Z640 Version -
Hp ≫ Z8 G4 Firmware Version 02.75
   Hp ≫ Z8 G4 Version -
Hp ≫ Z840 Firmware Version 2.58
   Hp ≫ Z840 Version -
Hp ≫ Zcentral 4r Firmware Version 01.18
   Hp ≫ Zcentral 4r Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.219
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://support.hp.com/us-en/document/ish_5670997-5671021-16/hpsbhf03770
Vendor Advisory