CVE-2021-3661
8.4
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.5 / Impact: 5.9
Source: NVD
Description
A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.
Affected (20)
Products: Hp: Z1 All In One G3 Firmware, Z2 Mini G3 Firmware, Z2 Mini G4 Firmware, Z2 Mini G5 Firmware, Z2 Small Form Factor G4 Firmware, Z2 Small Form Factor G5 Firmware, Z2 Small Form Factor G8 Firmware, Z2 Tower G4 Firmware, Z2 Tower G5 Firmware, Z2 Tower G8 Firmware, Z238 Microtower Firmware, Z240 Small Form Factor Firmware, Z240 Tower Firmware, Z4 G4 Firmware, Z440 Firmware, Z6 G4 Firmware, Z640 Firmware, Z8 G4 Firmware, Z840 Firmware, Zcentral 4r Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.31 |
| Running on/with | Platform Versions |
|---|---|
Hp Z1 All In One G3 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.83 |
| Running on/with | Platform Versions |
|---|---|
Hp Z2 Mini G3 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.08.01 |
| Running on/with | Platform Versions |
|---|---|
Hp Z2 Mini G4 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.03.00_rev_a |
| Running on/with | Platform Versions |
|---|---|
Hp Z2 Mini G5 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.08.01 |
| Running on/with | Platform Versions |
|---|---|
Hp Z2 Small Form Factor G4 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.03.00_rev_a |
| Running on/with | Platform Versions |
|---|---|
Hp Z2 Small Form Factor G5 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.03.00_rev_a |
| Running on/with | Platform Versions |
|---|---|
Hp Z2 Small Form Factor G8 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.08.01 |
| Running on/with | Platform Versions |
|---|---|
Hp Z2 Tower G4 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.03.00_rev_a |
| Running on/with | Platform Versions |
|---|---|
Hp Z2 Tower G5 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.03.00_rev_a |
| Running on/with | Platform Versions |
|---|---|
Hp Z2 Tower G8 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.83 |
| Running on/with | Platform Versions |
|---|---|
Hp Z238 Microtower | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.83 |
| Running on/with | Platform Versions |
|---|---|
Hp Z240 Small Form Factor | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.83 |
| Running on/with | Platform Versions |
|---|---|
Hp Z240 Tower | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 02.75 |
| Running on/with | Platform Versions |
|---|---|
Hp Z4 G4 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.58 |
| Running on/with | Platform Versions |
|---|---|
Hp Z440 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version 02.75 |
| Running on/with | Platform Versions |
|---|---|
Hp Z6 G4 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.58 |
| Running on/with | Platform Versions |
|---|---|
Hp Z640 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version 02.75 |
| Running on/with | Platform Versions |
|---|---|
Hp Z8 G4 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.58 |
| Running on/with | Platform Versions |
|---|---|
Hp Z840 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.18 |
| Running on/with | Platform Versions |
|---|---|
Hp Zcentral 4r | All versions |
References (2)
Source: hp-security-alert@hp.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.