8.4

CVE-2021-3661

A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpZ1 All-in-one G3 Firmware Version01.31
   HpZ1 All-in-one G3 Version-
HpZ2 Mini G3 Firmware Version01.83
   HpZ2 Mini G3 Version-
HpZ2 Mini G4 Firmware Version01.08.01
   HpZ2 Mini G4 Version-
HpZ2 Mini G5 Firmware Version01.03.00_rev_a
   HpZ2 Mini G5 Version-
HpZ2 Small Form Factor G4 Firmware Version01.08.01
   HpZ2 Small Form Factor G4 Version-
HpZ2 Small Form Factor G5 Firmware Version01.03.00_rev_a
   HpZ2 Small Form Factor G5 Version-
HpZ2 Small Form Factor G8 Firmware Version01.03.00_rev_a
   HpZ2 Small Form Factor G8 Version-
HpZ2 Tower G4 Firmware Version01.08.01
   HpZ2 Tower G4 Version-
HpZ2 Tower G5 Firmware Version01.03.00_rev_a
   HpZ2 Tower G5 Version-
HpZ2 Tower G8 Firmware Version01.03.00_rev_a
   HpZ2 Tower G8 Version-
HpZ238 Microtower Firmware Version01.83
   HpZ238 Microtower Version-
HpZ240 Small Form Factor Firmware Version01.83
   HpZ240 Small Form Factor Version-
HpZ240 Tower Firmware Version01.83
   HpZ240 Tower Version-
HpZ4 G4 Firmware Version02.75
   HpZ4 G4 Version-
HpZ440 Firmware Version2.58
   HpZ440 Version-
HpZ6 G4 Firmware Version02.75
   HpZ6 G4 Version-
HpZ640 Firmware Version2.58
   HpZ640 Version-
HpZ8 G4 Firmware Version02.75
   HpZ8 G4 Version-
HpZ840 Firmware Version2.58
   HpZ840 Version-
HpZcentral 4r Firmware Version01.18
   HpZcentral 4r Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.03% 0.766
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.