CVE-2017-2751

UnknownEPSS 1.06%

Last modified

CVE-2017-2751 is a vulnerability of currently unknown severity. A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. EPSS estimates a 1.06% chance of exploitation in the next 30 days.

Description

A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.

Metrics

EPSS Probability
1.06%

60.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpHp 240 G1 Firmware< f.48
HpHp 245 G1 Firmware< f.48
HpHp 1000-1300 Firmware< f.48
HpHp 250 G1 Notebook Pc Firmware< f.47
HpHp 255 G1 Notebook Pc Firmware< f.47
HpHp Envy 15-J000 Firmware< f.22
HpHp Envy 15-J100 Firmware< f.71
HpHp Pavilion 15-N000 Firmware< f.72
HpHp 246 Firmware< f.04
HpHp 455 Firmware< f.08
HpHp Envy 17 J100 Firmware< f.71
HpHp Envy 17-J100 Leap Motion Se Firmware< f.71
HpHp Split 13-G200 Firmware< f.25
HpHp Envy 100 Firmware< f.22
HpHp Pavilion 14-N000 Firmware< f.72
HpHp Envy 14-K100 Firmware< f.22
HpHp Spectre X2 13-Smb Pro Firmware< f.25
HpHp Spectre 13-H200 Firmware< f.25
HpHp Pavilion 15-N200 Firmware< f.72
HpHp Pavilion 15-N300 Firmware< f.72
HpHp Envy M6-N000 Firmware< f.26
HpHp 255 G3 Firmware< f.45
HpHp 14-G000 Firmware< f.45
HpHp Pavilion 11-N000 Firmware< f.2e
HpHp 15-R000 Firmware< f.43
HpHp 15-R500 Firmware< f.43
HpHp Pavilion 10-F000 Firmware< f.0e
HpHp G14-A000 Firmware< f.06
HpHp 14-R000 Firmware< f.43
HpHp 240 G3 Firmware< f.43
HpHp 246 G3 Firmware< f.43
HpCompaq Cq45-900 FirmwareAll versions
HpCompaq 14-H000 FirmwareAll versions
HpCompaq 14-S000 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-2751?
A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.
How severe is CVE-2017-2751?
Severity scoring for CVE-2017-2751 is pending analysis. The EPSS model estimates a 1.06% probability of exploitation in the next 30 days.
How do I fix CVE-2017-2751?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-2751?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST