ZeroHour

CVE-2019-18913

CVSS 3.1
6.8 medium
EPSS
<1%p47
Published
()
Modified
Description

A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks. This industry-wide issue requires physically accessing internal expansion slots with specialized hardware and software tools to modify UEFI code in memory. This affects HP Intel-based Business PCs that support Microsoft Windows 10 Kernel DMA protection. Affected versions depend on platform (prior to 01.04.02; or prior to 02.04.01; or prior to 02.04.02).

Vendors
hp
Products
elitedesk 800 g5 dm firmware, elitedesk 800 g5 sff firmware, elitedesk 800 g5 twr firmware, eliteone 800 g5 aio firmware, prodesk 400 g5 dm firmware, prodesk 400 g6 mt firmware, prodesk 400 g6 sff firmware, prodesk 480 g6 mt firmware, prodesk 600 g5 dm firmware, prodesk 600 g5 mt firmware, prodesk 600 g5 pci mt firmware, prodesk 600 g5 sff firmware
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.