CVE-2023-6215
Last modified
CVE-2023-6215 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A potential security vulnerability has been identified in HP Sure Start’s protection of the Intel Flash Descriptor in certain HP PC products, which might allow security bypass, arbitrary code execution, loss of integrity or confidentiality, or denial of service. HP is releasing BIOS updates to mitigate the potential vulnerability.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
A potential security vulnerability has been identified in HP Sure Start’s protection of the Intel Flash Descriptor in certain HP PC products, which might allow security bypass, arbitrary code execution, loss of integrity or confidentiality, or denial of service. HP is releasing BIOS updates to mitigate the potential vulnerability.
Metrics
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-6215?
How severe is CVE-2023-6215?
How do I fix CVE-2023-6215?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-6209Relative URLs starting with three slashes were incorrectly p…6.5
- CVE-2023-6210When an https: web page created a pop-up from a "javascript:…6.5
- CVE-2023-6211If an attacker needed a user to load an insecure http: page …6.5
- CVE-2023-6212Memory safety bugs present in Firefox 119, Firefox ESR 115.4…8.8
- CVE-2023-6213Memory safety bugs present in Firefox 119. Some of these bug…8.8
- CVE-2023-6214The HT Mega – Absolute Addons For Elementor plugin for WordP…7.5
- CVE-2023-6217 In Progress MOVEit Transfer versions released before 2022.0…6.1
- CVE-2023-6218 In Progress MOVEit Transfer versions released before 2022.0…7.2
- CVE-2023-6219The BookingPress plugin for WordPress is vulnerable to arbit…7.2
- CVE-2023-6220The Piotnet Forms plugin for WordPress is vulnerable to arbi…9.8
- CVE-2023-6221 The cloud provider MachineSense uses for integration and de…6.5
- CVE-2023-6222IThe Quttera Web Malware Scanner WordPress plugin before 3.4…7.2
Are you affected by CVE-2023-6215?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
