CVE-2021-3661

A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
hpCNA
---
---
CVEADP
---
---
CISA-ADPADP
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
hpz1_all-in-one_g3_firmware
01.31
hpz2_mini_g3_firmware
01.83
hpz2_mini_g4_firmware
01.08.01
hpz2_mini_g5_firmware
01.03.00_rev_a:_rev_a
hpz2_small_form_factor_g4_firmware
01.08.01
hpz2_small_form_factor_g5_firmware
01.03.00_rev_a:_rev_a
hpz2_small_form_factor_g8_firmware
01.03.00_rev_a:_rev_a
hpz2_tower_g4_firmware
01.08.01
hpz2_tower_g5_firmware
01.03.00_rev_a:_rev_a
hpz2_tower_g8_firmware
01.03.00_rev_a:_rev_a
hpz238_microtower_firmware
01.83
hpz240_small_form_factor_firmware
01.83
hpz240_tower_firmware
01.83
hpz4_g4_firmware
02.75
hpz440_firmware
2.58
hpz6_g4_firmware
02.75
hpz640_firmware
2.58
hpz8_g4_firmware
02.75
hpz840_firmware
2.58
hpzcentral_4r_firmware
01.18
𝑥
= Vulnerable software versions