CVE-2019-16284

HIGHCVSS 7.2/10EPSS 1.96%

Last modified

CVE-2019-16284 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code. EPSS estimates a 1.96% chance of exploitation in the next 30 days.

Description

A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code. A list of affected products and versions are available in https://support.hp.com/rs-en/document/c06456250.

Metrics

CVSS 3.1
7.2/10

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.96%

77.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Hp260 G1 Dm Firmware< 2.27
Hp280 Pro G1 Firmware< 80.3
Hp285 G2 Firmware< a0.23
Hp340 G3 Firmware< f.48
Hp340 G4 Firmware< f.55
Hp346 G3 Firmware< f.48
Hp346 G4 Firmware< f.46
Hp348 G3 Firmware< f.48
Hp348 G4 Firmware< f.55
HpElite Slice Firmware< 2.42
HpElite X2 1011 G1 Firmware< 1.27
HpElite X2 1012 G1 Firmware< 1.42
HpElitebook 1030 G1 Firmware< 1.42
HpElitebook 1040 G2 Firmware< 1.17
HpElitebook 720 G1 Firmware< 1.48
HpElitebook 720 G2 Firmware< 1.29
HpElitebook 740 G1 Firmware< 1.48
HpElitebook 740 G2 Firmware< 1.29
HpElitebook 750 G1 Firmware< 1.48
HpElitebook 750 G2 Firmware< 1.29
HpElitebook 820 G1 Firmware< 1.48
HpElitebook 820 G2 Firmware< 1.29
HpElitebook 820 G3 Firmware< 1.42
HpElitebook 828 G3 Firmware< 1.42
HpElitebook 840 G1 Firmware< 1.48
HpElitebook 840 G2 Firmware< 1.29
HpElitebook 840 G3 Firmware< 1.42
HpElitebook 848 G3 Firmware< 1.42
HpElitebook 850 G1 Firmware< 1.48
HpElitebook 850 G2 Firmware< 1.29
HpElitebook 850 G3 Firmware< 1.42
HpElitebook Folio 1020 G1 Firmware< 1.24
HpElitebook Folio 1040 G1 Firmware< 1.44
HpElitebook Folio 1040 G3 Firmware< 1.42
HpElitebook Folio 9480m Firmware< 1.49
HpElitebook Folio G1 Firmware< 1.42
HpElitebook Revolve 810 G2 Firmware< 1.45
HpElitebook Revolve 810 G3 Firmware< 1.2
HpElitedesk 800 G2 Dm Firmware< 2.42
HpElitedesk 800 G2 Sff Firmware< 2.42
HpElitedesk 800 G2 Twr Firmware< 2.42
HpEliteone 800 G2 Aio Firmware< 2.42
HpElitepad 1000 G2 Firmware< 1.48
HpMp9 G2 Retail System Firmware< 2.42
HpPro Tablet 10 Ee G1 Firmware< 1.31
HpPro Tablet 608 G1 Firmware< 1.21
HpPro Tablet 610 G1 Firmware< f.16
HpPro X2 612 G1 Firmware< 1.48
HpProbook 11 G1 Firmware< 1.17
HpProbook 11 G2 Firmware< 1.42

Showing 50 of 102 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-16284?
A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code. A list of affected products and versions are available in https://support.hp.com/rs-en/document/c06456250.
How severe is CVE-2019-16284?
CVE-2019-16284 has a CVSS score of 7.2/10 (HIGH severity). The EPSS model estimates a 1.96% probability of exploitation in the next 30 days.
How do I fix CVE-2019-16284?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-16284?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST