CVE-2023-26300
Last modified
CVE-2023-26300 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege. HP is releasing firmware updates to mitigate the potential vulnerability.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege. HP is releasing firmware updates to mitigate the potential vulnerability.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Desktop Pro A 300 G3 Firmware | < f.13 |
| Hp | Desktop Pro A G3 Firmware | < f.13 |
| Hp | Desktop Pro A G3 Microtower Firmware | < f.13 |
| Hp | Zhan 66 Pro A G1 R Microtower Firmware | < f.13 |
| Hp | T638 Thin Client Firmware | < 00.01.13 |
| Hp | Stream 11 Pro G5 Firmware | < f.18 |
| Hp | 240 G10 Firmware | < f.05 |
| Hp | 240 G6 Firmware | < f.55 |
| Hp | 240 G7 Firmware | < f.75 |
| Hp | 240 G9 Firmware | < f.06 |
| Hp | 245 G10 Firmware | < f.06 |
| Hp | 245 G7 Firmware | < f.70 |
| Hp | 245 G8 Firmware | < f.26 |
| Hp | 245 G9 Firmware | < f.11 |
| Hp | 245 Firmware | < f.11 |
| Hp | 246 G6 Firmware | < f.55 |
| Hp | 246 G7 Firmware | < f.75 |
| Hp | 247 G8 Firmware | < f.70 |
| Hp | 250 G10 Firmware | < f.06 |
| Hp | 250 G6 Firmware | < f.73 |
| Hp | 250 G7 Firmware | < f.46 |
| Hp | 250 G9 Firmware | < f.63 |
| Hp | 255 G10 Firmware | < f.09 |
| Hp | 255 G6 Firmware | < f.56 |
| Hp | 255 G7 Firmware | < f.41 |
| Hp | 255 G8 Firmware | < f.37 |
| Hp | 255 G9 Firmware | < f.12 |
| Hp | 256 G6 Firmware | < f.73 |
| Hp | 256 G7 Firmware | < f.46 |
| Hp | 258 G6 Firmware | < f.73 |
| Hp | 258 G7 Firmware | < f.46 |
| Hp | 340 G7 Firmware | < f.39 |
| Hp | 348 G7 Firmware | < f.39 |
| Hp | 470 G10 Firmware | < f.03 |
| Hp | 470 G7 Firmware | < f.70 |
| Hp | 470 G9 Firmware | < f.06 |
| Hp | Stream 11 Pro G4 Firmware | < f.30 |
| Hp | Zbook 15 G5 Mobile Workstation Firmware | < f.37 |
| Hp | Zhan 99 G3 Mobile Workstation Firmware | < f.19 |
| Hp | Zhan 99 G4 Mobile Workstation Firmware | < f.09 |
| Hp | 200 G4 22 All-In-One Pc \(Rom Family Ssid 86f2\) Firmware | < f.50 |
| Hp | 200 G4 22 All-In-One Pc \(Rom Family Ssid 86f3\) Firmware | < f.50 |
| Hp | 200 G4 22 All-In-One Pc \(Rom Family Ssid 86f0\) Firmware | < f.50 |
| Hp | 200 Pro G4 22 All-In-One Pc \(Rom Family Ssid 86f2\) Firmware | < f.50 |
| Hp | 200 Pro G4 22 All-In-One Pc \(Rom Family Ssid 86f3\) Firmware | < f.50 |
| Hp | 200 Pro G4 22 All-In-One Pc \(Rom Family Ssid 86f0\) Firmware | < f.50 |
| Hp | 205 G4 22 All-In-One Pc \(Rom Family Ssid 86f2\) Firmware | < f.50 |
| Hp | 205 G4 22 All-In-One Pc \(Rom Family Ssid 86f3\) Firmware | < f.50 |
| Hp | 205 G4 22 All-In-One Pc \(Rom Family Ssid 86f0\) Firmware | < f.50 |
| Hp | 205 G8 24 All-In-One Pc \(Rom Family Ssid 8923\) Firmware | < f.20 |
Showing 50 of 89 affected configurations. See NVD for the full list.
References
- https://support.hp.com/us-en/document/ish_9461800-9461828-16Patch, Vendor Advisory
- https://support.hp.com/us-en/document/ish_9461800-9461828-16Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-26300?
How severe is CVE-2023-26300?
How do I fix CVE-2023-26300?
Are you affected by CVE-2023-26300?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
