CVE-2023-26299

HIGHCVSS 7/10EPSS 0.13%

Last modified

CVE-2023-26299 is a high-severity vulnerability rated 7/10 on the CVSS scale. A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.

Description

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.

Metrics

CVSS 3.1
7/10

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.13%

2.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Hp260 G4 Desktop Mini Firmware< 2.14
HpT430 Firmware< 00.01.11
HpT628 Firmware< 00.01.10
Hp240 G10 Firmware< f.04
Hp245 G6 Firmware< f.35
Hp245 G7 Firmware< f.69
Hp245 G8 Firmware< f.25
Hp247 G8 Firmware< f.69
Hp250 G10 Firmware< f.05
Hp255 G10 Firmware< f.08
Hp349 G7 Firmware< f.28
Hp470 G10 Firmware< f.02
Hp470 G9 Firmware< f.05
HpZhan 99 G2 Firmware< f.24
HpZhan 99 G4 Firmware< f.08
HpVr Backpack G2 Firmware< f.28
Hp200 G3 FirmwareAll versions
Hp200 G4 22 All-In-One FirmwareAll versions
Hp200 Pro G4 22 All-In-One FirmwareAll versions
Hp205 G4 22 All-In-One FirmwareAll versions
Hp205 Pro G4 22 All-In-One FirmwareAll versions
Hp280 G3 FirmwareAll versions
Hp280 G4 FirmwareAll versions
Hp280 G4 Microtower FirmwareAll versions
Hp280 G5 FirmwareAll versions
Hp280 G5 Small Form Factor FirmwareAll versions
Hp280 G6 FirmwareAll versions
Hp280 G8 Microtower FirmwareAll versions
Hp280 Pro G3 FirmwareAll versions
Hp280 Pro G4 Microtower FirmwareAll versions
Hp280 Pro G5 Small Form Factor FirmwareAll versions
Hp282 G5 FirmwareAll versions
Hp282 G6 FirmwareAll versions
Hp282 Pro G4 Microtower FirmwareAll versions
Hp288 G5 FirmwareAll versions
Hp288 G6 FirmwareAll versions
Hp288 Pro G4 Microtower FirmwareAll versions
Hp290 G1 FirmwareAll versions
Hp290 G2 FirmwareAll versions
Hp290 G2 Microtower FirmwareAll versions
Hp290 G3 FirmwareAll versions
Hp290 G3 Small Form Factor FirmwareAll versions
Hp290 G4 FirmwareAll versions
HpDesktop Pro G1 Microtower FirmwareAll versions
HpPro Small Form Factor 280 G9 Desktop FirmwareAll versions
HpPro Small Form Factor 290 G9 Desktop FirmwareAll versions
HpPro Small Form Factor Zhan 66 G9 Desktop FirmwareAll versions
HpPro Tower 200 G9 Desktop FirmwareAll versions
HpPro Tower 280 G9 Desktop FirmwareAll versions
HpPro Tower 290 G9 Desktop FirmwareAll versions

Showing 50 of 59 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-26299?
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.
How severe is CVE-2023-26299?
CVE-2023-26299 has a CVSS score of 7/10 (HIGH severity). The EPSS model estimates a 0.13% probability of exploitation in the next 30 days.
How do I fix CVE-2023-26299?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-26299?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST