A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.

Project Subscriptions

Vendors Products
200 G3 Firmware Subscribe
200 G4 22 All-in-one Subscribe
200 G4 22 All-in-one Firmware Subscribe
200 Pro G4 22 All-in-one Subscribe
200 Pro G4 22 All-in-one Firmware Subscribe
205 G4 22 All-in-one Subscribe
205 G4 22 All-in-one Firmware Subscribe
205 Pro G4 22 All-in-one Subscribe
205 Pro G4 22 All-in-one Firmware Subscribe
240 G10 Subscribe
240 G10 Firmware Subscribe
245 G6 Firmware Subscribe
245 G7 Firmware Subscribe
245 G8 Firmware Subscribe
247 G8 Firmware Subscribe
250 G10 Subscribe
250 G10 Firmware Subscribe
255 G10 Subscribe
255 G10 Firmware Subscribe
260 G4 Desktop Mini Subscribe
260 G4 Desktop Mini Firmware Subscribe
280 G3 Firmware Subscribe
280 G4 Firmware Subscribe
280 G4 Microtower Subscribe
280 G4 Microtower Firmware Subscribe
280 G5 Firmware Subscribe
280 G5 Small Form Factor Subscribe
280 G5 Small Form Factor Firmware Subscribe
280 G6 Firmware Subscribe
280 G8 Microtower Subscribe
280 G8 Microtower Firmware Subscribe
280 Pro G3 Subscribe
280 Pro G3 Firmware Subscribe
280 Pro G4 Microtower Subscribe
280 Pro G4 Microtower Firmware Subscribe
280 Pro G5 Small Form Factor Subscribe
280 Pro G5 Small Form Factor Firmware Subscribe
282 G5 Firmware Subscribe
282 G6 Firmware Subscribe
282 Pro G4 Microtower Subscribe
282 Pro G4 Microtower Firmware Subscribe
288 G5 Firmware Subscribe
288 G6 Firmware Subscribe
288 Pro G4 Microtower Subscribe
288 Pro G4 Microtower Firmware Subscribe
290 G1 Firmware Subscribe
290 G2 Firmware Subscribe
290 G2 Microtower Subscribe
290 G2 Microtower Firmware Subscribe
290 G3 Firmware Subscribe
290 G3 Small Form Factor Subscribe
290 G3 Small Form Factor Firmware Subscribe
290 G4 Firmware Subscribe
349 G7 Firmware Subscribe
470 G10 Subscribe
470 G10 Firmware Subscribe
470 G9 Firmware Subscribe
Desktop Pro G1 Microtower Subscribe
Desktop Pro G1 Microtower Firmware Subscribe
Pro Small Form Factor 280 G9 Desktop Subscribe
Pro Small Form Factor 280 G9 Desktop Firmware Subscribe
Pro Small Form Factor 290 G9 Desktop Subscribe
Pro Small Form Factor 290 G9 Desktop Firmware Subscribe
Pro Small Form Factor Zhan 66 G9 Desktop Subscribe
Pro Small Form Factor Zhan 66 G9 Desktop Firmware Subscribe
Pro Tower 200 G9 Desktop Subscribe
Pro Tower 200 G9 Desktop Firmware Subscribe
Pro Tower 280 G9 Desktop Subscribe
Pro Tower 280 G9 Desktop Firmware Subscribe
Pro Tower 290 G9 Desktop Subscribe
Pro Tower 290 G9 Desktop Firmware Subscribe
Pro Tower Zhan 99 G9 Desktop Subscribe
Pro Tower Zhan 99 G9 Desktop Firmware Subscribe
Proone 240 G10 Subscribe
Proone 240 G10 Firmware Subscribe
Proone 240 G9 Subscribe
Proone 240 G9 Firmware Subscribe
Proone 440 G3 Subscribe
Proone 440 G3 Firmware Subscribe
Proone 490 G3 Subscribe
Proone 490 G3 Firmware Subscribe
Proone 496 G3 Subscribe
Proone 496 G3 Firmware Subscribe
T430 Firmware Subscribe
T628 Firmware Subscribe
Vr Backpack G2 Subscribe
Vr Backpack G2 Firmware Subscribe
Z Vr Backpack G1 Workstation Subscribe
Z Vr Backpack G1 Workstation Firmware Subscribe
Zhan 86 Pro G2 Microtower Subscribe
Zhan 86 Pro G2 Microtower Firmware Subscribe
Zhan 99 G2 Subscribe
Zhan 99 G2 Firmware Subscribe
Zhan 99 G4 Subscribe
Zhan 99 G4 Firmware Subscribe
Zhan 99 Pro G1 Microtower Subscribe
Zhan 99 Pro G1 Microtower Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-30122 A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 04 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2024-12-04T16:06:16.624Z

Reserved: 2023-02-21T21:14:33.320Z

Link: CVE-2023-26299

cve-icon Vulnrichment

Updated: 2024-08-02T11:46:24.488Z

cve-icon NVD

Status : Modified

Published: 2023-06-30T16:15:09.543

Modified: 2024-11-21T07:51:05.217

Link: CVE-2023-26299

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses