← Back

CVE-2019-18913

nvd nist
Published: Jan 31, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD

Description

A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks. This industry-wide issue requires physically accessing internal expansion slots with specialized hardware and software tools to modify UEFI code in memory. This affects HP Intel-based Business PCs that support Microsoft Windows 10 Kernel DMA protection. Affected versions depend on platform (prior to 01.04.02; or prior to 02.04.01; or prior to 02.04.02).

Affected (33)

Products: Hp: Elitedesk 800 G5 Dm Firmware, Elitedesk 800 G5 Sff Firmware, Elitedesk 800 G5 Twr Firmware, Eliteone 800 G5 Aio Firmware, Prodesk 400 G5 Dm Firmware, Prodesk 400 G6 Mt Firmware, Prodesk 400 G6 Sff Firmware, Prodesk 480 G6 Mt Firmware, Prodesk 600 G5 Dm Firmware, Prodesk 600 G5 Mt Firmware, Prodesk 600 G5 Pci Mt Firmware, Prodesk 600 G5 Sff Firmware, Proone 400 G5 Aio Firmware, Proone 440 G5 Aio Firmware, Proone 600 G5 Aio Firmware, Elite Dragonfly Firmware, Elite X2 G4 Firmware, Elitebook 830 G6 Firmware, Elitebook 836 G6 Firmware, Elitebook 840 G6 Firmware, Elitebook 840 G6 Healthcare Edition Firmware, Elitebook 846 G6 Firmware, Elitebook 846 G6 Healthcare Edition Firmware, Elitebook 850 G6 Firmware, Elitebook X360 1030 G4 Firmware, Elitebook X360 1040 G6 Firmware, Elitebook X360 830 G6 Firmware, Probook 640 G5 Firmware, Probook 650 G5 Firmware, Zbook 14u G6 Mobile Workstation Firmware, Zbook 15u G6 Mobile Workstation Firmware, Zhan X 13 G2 Firmware, Zbook 17u G6 Mobile Workstation Firmware
33 products
Elitedesk 800 G5 Dm Firmware
Elitedesk 800 G5 Sff Firmware
Elitedesk 800 G5 Twr Firmware
Eliteone 800 G5 Aio Firmware
Prodesk 400 G5 Dm Firmware
Prodesk 400 G6 Mt Firmware
Prodesk 400 G6 Sff Firmware
Prodesk 480 G6 Mt Firmware
Prodesk 600 G5 Dm Firmware
Prodesk 600 G5 Mt Firmware
Prodesk 600 G5 Pci Mt Firmware
Prodesk 600 G5 Sff Firmware
Proone 400 G5 Aio Firmware
Proone 440 G5 Aio Firmware
Proone 600 G5 Aio Firmware
Elite Dragonfly Firmware
Elite X2 G4 Firmware
Elitebook 830 G6 Firmware
Elitebook 836 G6 Firmware
Elitebook 840 G6 Firmware
Elitebook 846 G6 Firmware
Elitebook 850 G6 Firmware
Elitebook X360 1030 G4 Firmware
Elitebook X360 1040 G6 Firmware
Elitebook X360 830 G6 Firmware
Probook 640 G5 Firmware
Probook 650 G5 Firmware
Zhan X 13 G2 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.02
Running on/withPlatform Versions
Hp
Elitedesk 800 G5 Dm
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.02
Running on/withPlatform Versions
Hp
Elitedesk 800 G5 Sff
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.02
Running on/withPlatform Versions
Hp
Elitedesk 800 G5 Twr
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.02
Running on/withPlatform Versions
Hp
Eliteone 800 G5 Aio
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.01
Running on/withPlatform Versions
Hp
Prodesk 400 G5 Dm
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.01
Running on/withPlatform Versions
Hp
Prodesk 400 G6 Mt
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.02
Running on/withPlatform Versions
Hp
Prodesk 400 G6 Sff
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.01
Running on/withPlatform Versions
Hp
Prodesk 480 G6 Mt
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.01
Running on/withPlatform Versions
Hp
Prodesk 600 G5 Dm
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.01
Running on/withPlatform Versions
Hp
Prodesk 600 G5 Mt
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.01
Running on/withPlatform Versions
Hp
Prodesk 600 G5 Pci Mt
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.01
Running on/withPlatform Versions
Hp
Prodesk 600 G5 Sff
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.01
Running on/withPlatform Versions
Hp
Proone 400 G5 Aio
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.01
Running on/withPlatform Versions
Hp
Proone 440 G5 Aio
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 02.04.01
Running on/withPlatform Versions
Hp
Proone 600 G5 Aio
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Elite Dragonfly
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Elite X2 G4
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Elitebook 830 G6
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Elitebook 836 G6
All versions
Configuration T
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Elitebook 840 G6
All versions
Configuration U
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Elitebook 840 G6 Healthcare Edition
All versions
Configuration V
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Elitebook 846 G6
All versions
Configuration W
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Elitebook 846 G6 Healthcare Edition
All versions
Configuration X
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Elitebook 850 G6
All versions
Configuration Y
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Elitebook X360 1030 G4
All versions
Configuration Z
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Elitebook X360 1040 G6
All versions
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Elitebook X360 830 G6
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Probook 640 G5
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Probook 650 G5
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Zbook 14u G6 Mobile Workstation
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Zbook 15u G6 Mobile Workstation
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Zhan X 13 G2
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 01.04.02
Running on/withPlatform Versions
Hp
Zbook 17u G6 Mobile Workstation
All versions

References (2)

Source: hp-security-alert@hp.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.