CVE-2021-3809
Last modified
CVE-2021-3809 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Elite Dragonfly Firmware | 01.12.00 |
| Hp | Elite X2 1012 G2 Firmware | 1.41 |
| Hp | Elite X2 1013 G3 Firmware | 01.19.00 |
| Hp | Elite X2 G4 Firmware | 01.12.00 |
| Hp | Elitebook 1040 G4 Firmware | 1.41 |
| Hp | Elitebook 1050 G1 Firmware | 01.19.00 |
| Hp | Elitebook 725 G4 Firmware | 1.4 |
| Hp | Elitebook 735 G5 Firmware | 01.20.00 |
| Hp | Elitebook 735 G6 Firmware | 01.19.00 |
| Hp | Elitebook 745 G4 Firmware | 1.4 |
| Hp | Elitebook 745 G5 Firmware | 01.20.00 |
| Hp | Elitebook 745 G6 Firmware | 01.19.00 |
| Hp | Elitebook 755 G4 Firmware | 1.4 |
| Hp | Elitebook 755 G5 Firmware | 01.20.00 |
| Hp | Elitebook 820 G4 Firmware | 1.41 |
| Hp | Elitebook 828 G4 Firmware | 1.41 |
| Hp | Elitebook 830 G5 Firmware | 01.19.00 |
| Hp | Elitebook 830 G6 Firmware | 01.12.00 |
| Hp | Elitebook 836 G5 Firmware | 01.19.00 |
| Hp | Elitebook 836 G6 Firmware | 01.12.00 |
| Hp | Elitebook 840 G4 Firmware | 1.41 |
| Hp | Elitebook 840 G5 Firmware | 01.19.00 |
| Hp | Elitebook 840 G6 Firmware | 01.12.00 |
| Hp | Elitebook 840r G4 Firmware | 01.19.00 |
| Hp | Elitebook 846 G5 Firmware | 01.19.00 |
| Hp | Elitebook 848 G4 Firmware | 1.41 |
| Hp | Elitebook 850 G4 Firmware | 1.41 |
| Hp | Elitebook 850 G5 Firmware | 01.19.00 |
| Hp | Elitebook 850 G6 Firmware | 01.12.00 |
| Hp | Elitebook X360 1020 G2 Firmware | 1.41 |
| Hp | Elitebook X360 1030 G2 Firmware | 1.41 |
| Hp | Elitebook X360 1030 G3 Firmware | 01.19.00 |
| Hp | Elitebook X360 1030 G4 Firmware | 01.12.00 |
| Hp | Elitebook X360 1040 G5 Firmware | 01.19.00 |
| Hp | Elitebook X360 1040 G6 Firmware | 01.12.00 |
| Hp | Elitebook X360 830 G5 Firmware | 01.19.00 |
| Hp | Elitebook X360 830 G6 Firmware | 01.12.00 |
| Hp | Pro X2 612 G2 Firmware | 1.41 |
| Hp | Probook 11 Ee G2 Firmware | 1.55 |
| Hp | Probook 430 G4 Firmware | 1.41 |
| Hp | Probook 430 G5 Firmware | 01.20.00 |
| Hp | Probook 430 G6 Firmware | 01.19.00 |
| Hp | Probook 440 G4 Firmware | 1.41 |
| Hp | Probook 440 G5 Firmware | 01.20.00 |
| Hp | Probook 440 G6 Firmware | 01.19.00 |
| Hp | Probook 445 G6 Firmware | 01.19.00 |
| Hp | Probook 445r G6 Firmware | 01.19.00 |
| Hp | Probook 450 G4 Firmware | 1.41 |
| Hp | Probook 450 G5 Firmware | 01.20.00 |
| Hp | Probook 450 G6 Firmware | 01.19.00 |
Showing 50 of 181 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3809?
How severe is CVE-2021-3809?
How do I fix CVE-2021-3809?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-38084An issue was discovered in the POP3 component of Courier Mai…8.1
- CVE-2021-38085The Canon TR150 print driver through 3.71.2.10 is vulnerable…7.8
- CVE-2021-38086Acronis Cyber Protect 15 for Windows prior to build 27009 an…7.8
- CVE-2021-38087Reflected cross-site scripting (XSS) was possible on the log…6.1
- CVE-2021-38088Acronis Cyber Protect 15 for Windows prior to build 27009 al…7.8
- CVE-2021-38089Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-38090Integer Overflow vulnerability in function filter16_roberts …8.8
- CVE-2021-38091Integer Overflow vulnerability in function filter16_sobel in…8.8
- CVE-2021-38092Integer Overflow vulnerability in function filter_prewitt in…8.8
- CVE-2021-38093Integer Overflow vulnerability in function filter_robert in …8.8
- CVE-2021-38094Integer Overflow vulnerability in function filter_sobel in l…8.8
- CVE-2021-38095The REST API in Planview Spigit 4.5.3 allows remote unauthen…7.5
Are you affected by CVE-2021-3809?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
