CVE-2021-3439

HIGHCVSS 7.8/10EPSS 0.17%

Last modified

CVE-2021-3439 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.17%

7.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Hp340 G3 Firmware< f.52
Hp340 G4 Firmware< f.62
Hp346 G3 Firmware< f.52
Hp346 G4 Firmware< f.50
Hp348 G3 Firmware< f.52
Hp348 G4 Firmware< f.62
HpElite Dragonfly Firmware< 01.09.00
HpElite Dragonfly G2 Firmware< 01.04.01
HpElite Dragonfly Max Firmware< 01.04.01
HpElite X2 1012 G1 Firmware< 1.52
HpElite X2 1012 G1 Tablet Firmware< 1.52
HpElite X2 1012 G2 Firmware< 1.39
HpElite X2 1013 G3 Firmware< 01.16.00
HpElite X2 G4 Firmware< 01.09.00
HpElitebook 1030 G1 Firmware< 1.52
HpElitebook 1040 G3 Firmware< 1.52
HpElitebook 1040 G4 Firmware< 1.39
HpElitebook 1050 G1 Firmware< 1.16
HpElitebook 820 G3 Firmware< 1.52
HpElitebook 820 G4 Firmware< 1.39
HpElitebook 828 G3 Firmware< 1.52
HpElitebook 828 G4 Firmware< 1.39
HpElitebook 830 G5 Firmware< 01.16.00
HpElitebook 830 G6 Firmware< 01.09.00
HpElitebook 830 G7 Firmware< 01.05.00
HpElitebook 836 G5 Firmware< 01.16.00
HpElitebook 836 G6 Firmware< 01.09.00
HpElitebook 840 G3 Firmware< 1.52
HpElitebook 840 G4 Firmware< 1.39
HpElitebook 840 G5 Firmware< 01.16.00
HpElitebook 840 G5 Healthcare Edition Firmware< 01.16.00
HpElitebook 840 G6 Firmware< 01.09.00
HpElitebook 840 G6 Healthcare Edition Firmware< 01.09.00
HpElitebook 840 G7 Firmware< 01.05.00
HpElitebook 840r G4 Firmware< 01.16.00
HpElitebook 846 G5 Firmware< 01.16.00
HpElitebook 848 G3 Firmware< 1.52
HpElitebook 848 G4 Firmware< 1.39
HpElitebook 850 G3 Firmware< 1.52
HpElitebook 850 G4 Firmware< 1.39
HpElitebook 850 G5 Firmware< 01.16.00
HpElitebook 850 G6 Firmware< 01.09.00
HpElitebook 850 G7 Firmware< 01.05.00
HpElitebook Folio G1 Firmware< 1.52
HpElitebook X360 1020 G2 Firmware< 1.39
HpElitebook X360 1030 G2 Firmware< 1.39
HpElitebook X360 1030 G3 Firmware< 01.16.00
HpElitebook X360 1030 G4 Firmware< 01.09.00
HpElitebook X360 1030 G7 Firmware< 01.05.00
HpElitebook X360 1030 G8 Firmware< 01.04.01

Showing 50 of 377 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-3439?
HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities.
How severe is CVE-2021-3439?
CVE-2021-3439 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2021-3439?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-3439?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST