CVE-2019-16284
Last modified
CVE-2019-16284 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code. EPSS estimates a 1.96% chance of exploitation in the next 30 days.
Description
A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code. A list of affected products and versions are available in https://support.hp.com/rs-en/document/c06456250.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | 260 G1 Dm Firmware | < 2.27 |
| Hp | 280 Pro G1 Firmware | < 80.3 |
| Hp | 285 G2 Firmware | < a0.23 |
| Hp | 340 G3 Firmware | < f.48 |
| Hp | 340 G4 Firmware | < f.55 |
| Hp | 346 G3 Firmware | < f.48 |
| Hp | 346 G4 Firmware | < f.46 |
| Hp | 348 G3 Firmware | < f.48 |
| Hp | 348 G4 Firmware | < f.55 |
| Hp | Elite Slice Firmware | < 2.42 |
| Hp | Elite X2 1011 G1 Firmware | < 1.27 |
| Hp | Elite X2 1012 G1 Firmware | < 1.42 |
| Hp | Elitebook 1030 G1 Firmware | < 1.42 |
| Hp | Elitebook 1040 G2 Firmware | < 1.17 |
| Hp | Elitebook 720 G1 Firmware | < 1.48 |
| Hp | Elitebook 720 G2 Firmware | < 1.29 |
| Hp | Elitebook 740 G1 Firmware | < 1.48 |
| Hp | Elitebook 740 G2 Firmware | < 1.29 |
| Hp | Elitebook 750 G1 Firmware | < 1.48 |
| Hp | Elitebook 750 G2 Firmware | < 1.29 |
| Hp | Elitebook 820 G1 Firmware | < 1.48 |
| Hp | Elitebook 820 G2 Firmware | < 1.29 |
| Hp | Elitebook 820 G3 Firmware | < 1.42 |
| Hp | Elitebook 828 G3 Firmware | < 1.42 |
| Hp | Elitebook 840 G1 Firmware | < 1.48 |
| Hp | Elitebook 840 G2 Firmware | < 1.29 |
| Hp | Elitebook 840 G3 Firmware | < 1.42 |
| Hp | Elitebook 848 G3 Firmware | < 1.42 |
| Hp | Elitebook 850 G1 Firmware | < 1.48 |
| Hp | Elitebook 850 G2 Firmware | < 1.29 |
| Hp | Elitebook 850 G3 Firmware | < 1.42 |
| Hp | Elitebook Folio 1020 G1 Firmware | < 1.24 |
| Hp | Elitebook Folio 1040 G1 Firmware | < 1.44 |
| Hp | Elitebook Folio 1040 G3 Firmware | < 1.42 |
| Hp | Elitebook Folio 9480m Firmware | < 1.49 |
| Hp | Elitebook Folio G1 Firmware | < 1.42 |
| Hp | Elitebook Revolve 810 G2 Firmware | < 1.45 |
| Hp | Elitebook Revolve 810 G3 Firmware | < 1.2 |
| Hp | Elitedesk 800 G2 Dm Firmware | < 2.42 |
| Hp | Elitedesk 800 G2 Sff Firmware | < 2.42 |
| Hp | Elitedesk 800 G2 Twr Firmware | < 2.42 |
| Hp | Eliteone 800 G2 Aio Firmware | < 2.42 |
| Hp | Elitepad 1000 G2 Firmware | < 1.48 |
| Hp | Mp9 G2 Retail System Firmware | < 2.42 |
| Hp | Pro Tablet 10 Ee G1 Firmware | < 1.31 |
| Hp | Pro Tablet 608 G1 Firmware | < 1.21 |
| Hp | Pro Tablet 610 G1 Firmware | < f.16 |
| Hp | Pro X2 612 G1 Firmware | < 1.48 |
| Hp | Probook 11 G1 Firmware | < 1.17 |
| Hp | Probook 11 G2 Firmware | < 1.42 |
Showing 50 of 102 affected configurations. See NVD for the full list.
References
- https://support.hp.com/rs-en/document/c06456250Vendor Advisory
- https://support.hp.com/rs-en/document/c06456250Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-16284?
How severe is CVE-2019-16284?
How do I fix CVE-2019-16284?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-16278Directory Traversal in the function http_verify in nostromo …9.8
- CVE-2019-16279A memory error in the function SSL_accept in nostromo nhttpd…7.5
- CVE-2019-1628A vulnerability in the web server of Cisco Integrated Manage…5.5
- CVE-2019-16281Ptarmigan before 0.2.3 lacks API token validation, e.g., an …7.5
- CVE-2019-16282In NCH Express Invoice v7.12, persistent cross site scriptin…5.4
- CVE-2019-16283A potential security vulnerability has been identified with …7.8
- CVE-2019-16285If a local user has been configured and logged in, an unauth…4.6
- CVE-2019-16286An attacker may be able to bypass the OS application filter …6.8
- CVE-2019-16287In HP ThinPro Linux 6.2, 6.2.1, 7.0 and 7.1, an attacker may…6.8
- CVE-2019-16288On Tenda N301 wireless routers, a long string in the wifiSSI…7.5
- CVE-2019-16289The insert-php (aka Woody ad snippets) plugin before 2.2.8 f…5.4
- CVE-2019-1629A vulnerability in the configuration import utility of Cisco…5.3
Are you affected by CVE-2019-16284?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
