ZeroHour

CVE-2023-26299

CVSS 3.1
7.0 high
EPSS
<1%p3
Published
()
Modified
Description

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.

Vendors
hp
Products
260 g4 desktop mini firmware, t430 firmware, t628 firmware, 240 g10 firmware, 245 g6 firmware, 245 g7 firmware, 245 g8 firmware, 247 g8 firmware, 250 g10 firmware, 255 g10 firmware, 349 g7 firmware, 470 g10 firmware
Weakness
CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.