CVE-2023-26299
Last modified
CVE-2023-26299 is a high-severity vulnerability rated 7/10 on the CVSS scale. A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | 260 G4 Desktop Mini Firmware | < 2.14 |
| Hp | T430 Firmware | < 00.01.11 |
| Hp | T628 Firmware | < 00.01.10 |
| Hp | 240 G10 Firmware | < f.04 |
| Hp | 245 G6 Firmware | < f.35 |
| Hp | 245 G7 Firmware | < f.69 |
| Hp | 245 G8 Firmware | < f.25 |
| Hp | 247 G8 Firmware | < f.69 |
| Hp | 250 G10 Firmware | < f.05 |
| Hp | 255 G10 Firmware | < f.08 |
| Hp | 349 G7 Firmware | < f.28 |
| Hp | 470 G10 Firmware | < f.02 |
| Hp | 470 G9 Firmware | < f.05 |
| Hp | Zhan 99 G2 Firmware | < f.24 |
| Hp | Zhan 99 G4 Firmware | < f.08 |
| Hp | Vr Backpack G2 Firmware | < f.28 |
| Hp | 200 G3 Firmware | All versions |
| Hp | 200 G4 22 All-In-One Firmware | All versions |
| Hp | 200 Pro G4 22 All-In-One Firmware | All versions |
| Hp | 205 G4 22 All-In-One Firmware | All versions |
| Hp | 205 Pro G4 22 All-In-One Firmware | All versions |
| Hp | 280 G3 Firmware | All versions |
| Hp | 280 G4 Firmware | All versions |
| Hp | 280 G4 Microtower Firmware | All versions |
| Hp | 280 G5 Firmware | All versions |
| Hp | 280 G5 Small Form Factor Firmware | All versions |
| Hp | 280 G6 Firmware | All versions |
| Hp | 280 G8 Microtower Firmware | All versions |
| Hp | 280 Pro G3 Firmware | All versions |
| Hp | 280 Pro G4 Microtower Firmware | All versions |
| Hp | 280 Pro G5 Small Form Factor Firmware | All versions |
| Hp | 282 G5 Firmware | All versions |
| Hp | 282 G6 Firmware | All versions |
| Hp | 282 Pro G4 Microtower Firmware | All versions |
| Hp | 288 G5 Firmware | All versions |
| Hp | 288 G6 Firmware | All versions |
| Hp | 288 Pro G4 Microtower Firmware | All versions |
| Hp | 290 G1 Firmware | All versions |
| Hp | 290 G2 Firmware | All versions |
| Hp | 290 G2 Microtower Firmware | All versions |
| Hp | 290 G3 Firmware | All versions |
| Hp | 290 G3 Small Form Factor Firmware | All versions |
| Hp | 290 G4 Firmware | All versions |
| Hp | Desktop Pro G1 Microtower Firmware | All versions |
| Hp | Pro Small Form Factor 280 G9 Desktop Firmware | All versions |
| Hp | Pro Small Form Factor 290 G9 Desktop Firmware | All versions |
| Hp | Pro Small Form Factor Zhan 66 G9 Desktop Firmware | All versions |
| Hp | Pro Tower 200 G9 Desktop Firmware | All versions |
| Hp | Pro Tower 280 G9 Desktop Firmware | All versions |
| Hp | Pro Tower 290 G9 Desktop Firmware | All versions |
Showing 50 of 59 affected configurations. See NVD for the full list.
References
- https://support.hp.com/us-en/document/ish_8642715-8642746-16/hpsbhf03850Patch, Vendor Advisory
- https://support.hp.com/us-en/document/ish_8642715-8642746-16/hpsbhf03850Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-26299?
How severe is CVE-2023-26299?
How do I fix CVE-2023-26299?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-26293A vulnerability has been identified in Totally Integrated Au…7.3
- CVE-2023-26294Previous versions of HP Device Manager (prior to HPDM 5.0.10…7.8
- CVE-2023-26295Previous versions of HP Device Manager (prior to HPDM 5.0.10…9.8
- CVE-2023-26296Previous versions of HP Device Manager (prior to HPDM 5.0.10…8.8
- CVE-2023-26297Previous versions of HP Device Manager (prior to HPDM 5.0.10…8.8
- CVE-2023-26298Previous versions of HP Device Manager (prior to HPDM 5.0.10…8.8
- CVE-2023-2630Cross-site Scripting (XSS) - Stored in GitHub repository pim…4.8
- CVE-2023-26300A potential security vulnerability has been identified in th…7.8
- CVE-2023-26301Certain HP LaserJet Pro print products are potentially vulne…9.8
- CVE-2023-26302Denial of service could be caused to the command line interf…5.5
- CVE-2023-26303Denial of service could be caused to markdown-it-py, before …5.5
- CVE-2023-26309A remote code execution vulnerability in the webview compone…9.8
Are you affected by CVE-2023-26299?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
