7

CVE-2023-26299

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp260 G4 Desktop Mini Firmware Version < 2.14
   Hp260 G4 Desktop Mini Version-
HpT430 Firmware Version < 00.01.11
   HpT430 Version-
HpT628 Firmware Version < 00.01.10
   HpT628 Version-
Hp240 G10 Firmware Version < f.04
   Hp240 G10 Version-
Hp245 G6 Firmware Version < f.35
   Hp245 G6 Version-
Hp245 G7 Firmware Version < f.69
   Hp245 G7 Version-
Hp245 G8 Firmware Version < f.25
   Hp245 G8 Version-
Hp247 G8 Firmware Version < f.69
   Hp247 G8 Version-
Hp250 G10 Firmware Version < f.05
   Hp250 G10 Version-
Hp255 G10 Firmware Version < f.08
   Hp255 G10 Version-
Hp349 G7 Firmware Version < f.28
   Hp349 G7 Version-
Hp470 G10 Firmware Version < f.02
   Hp470 G10 Version-
Hp470 G9 Firmware Version < f.05
   Hp470 G9 Version-
HpZhan 99 G2 Firmware Version < f.24
   HpZhan 99 G2 Version-
HpZhan 99 G4 Firmware Version < f.08
   HpZhan 99 G4 Version-
HpVr Backpack G2 Firmware Version < f.28
   HpVr Backpack G2 Version-
Hp200 G3 Firmware Version-
   Hp200 G3 Version-
Hp200 G4 22 All-in-one Firmware Version-
   Hp200 G4 22 All-in-one Version-
Hp205 G4 22 All-in-one Firmware Version-
   Hp205 G4 22 All-in-one Version-
Hp280 G3 Firmware Version-
   Hp280 G3 Version-
Hp280 G4 Firmware Version-
   Hp280 G4 Version-
Hp280 G4 Microtower Firmware Version-
   Hp280 G4 Microtower Version-
Hp280 G5 Firmware Version-
   Hp280 G5 Version-
Hp280 G6 Firmware Version-
   Hp280 G6 Version-
Hp280 G8 Microtower Firmware Version-
   Hp280 G8 Microtower Version-
Hp280 Pro G3 Firmware Version-
   Hp280 Pro G3 Version-
Hp280 Pro G4 Microtower Firmware Version-
   Hp280 Pro G4 Microtower Version-
Hp282 G5 Firmware Version-
   Hp282 G5 Version-
Hp282 G6 Firmware Version-
   Hp282 G6 Version-
Hp282 Pro G4 Microtower Firmware Version-
   Hp282 Pro G4 Microtower Version-
Hp288 G5 Firmware Version-
   Hp288 G5 Version-
Hp288 G6 Firmware Version-
   Hp288 G6 Version-
Hp288 Pro G4 Microtower Firmware Version-
   Hp288 Pro G4 Microtower Version-
Hp290 G1 Firmware Version-
   Hp290 G1 Version-
Hp290 G2 Firmware Version-
   Hp290 G2 Version-
Hp290 G2 Microtower Firmware Version-
   Hp290 G2 Microtower Version-
Hp290 G3 Firmware Version-
   Hp290 G3 Version-
Hp290 G4 Firmware Version-
   Hp290 G4 Version-
HpProone 240 G10 Firmware Version-
   HpProone 240 G10 Version-
HpProone 240 G9 Firmware Version-
   HpProone 240 G9 Version-
HpProone 440 G3 Firmware Version-
   HpProone 440 G3 Version-
HpProone 490 G3 Firmware Version-
   HpProone 490 G3 Version-
HpProone 496 G3 Firmware Version-
   HpProone 496 G3 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.372
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.