CVE-2023-26299
EUVD-2023-3012230.06.2023, 16:15
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hp | 260_g4_desktop_mini_firmware | 𝑥 < 2.14 |
| hp | t430_firmware | 𝑥 < 00.01.11 |
| hp | t628_firmware | 𝑥 < 00.01.10 |
| hp | 200_g3_firmware | - |
| hp | 200_g4_22_all-in-one_firmware | - |
| hp | 200_pro_g4_22_all-in-one_firmware | - |
| hp | 205_g4_22_all-in-one_firmware | - |
| hp | 205_pro_g4_22_all-in-one_firmware | - |
| hp | 280_g3_firmware | - |
| hp | 280_g4_firmware | - |
| hp | 280_g4_microtower_firmware | - |
| hp | 280_g5_firmware | - |
| hp | 280_g5_small_form_factor_firmware | - |
| hp | 280_g6_firmware | - |
| hp | 280_g8_microtower_firmware | - |
| hp | 280_pro_g3_firmware | - |
| hp | 280_pro_g4_microtower_firmware | - |
| hp | 280_pro_g5_small_form_factor_firmware | - |
| hp | 282_g5_firmware | - |
| hp | 282_g6_firmware | - |
| hp | 282_pro_g4_microtower_firmware | - |
| hp | 288_g5_firmware | - |
| hp | 288_g6_firmware | - |
| hp | 288_pro_g4_microtower_firmware | - |
| hp | 290_g1_firmware | - |
| hp | 290_g2_firmware | - |
| hp | 290_g2_microtower_firmware | - |
| hp | 290_g3_firmware | - |
| hp | 290_g3_small_form_factor_firmware | - |
| hp | 290_g4_firmware | - |
| hp | desktop_pro_g1_microtower_firmware | - |
| hp | pro_small_form_factor_280_g9_desktop_firmware | - |
| hp | pro_small_form_factor_290_g9_desktop_firmware | - |
| hp | pro_small_form_factor_zhan_66_g9_desktop_firmware | - |
| hp | pro_tower_200_g9_desktop_firmware | - |
| hp | pro_tower_280_g9_desktop_firmware | - |
| hp | pro_tower_290_g9_desktop_firmware | - |
| hp | pro_tower_zhan_99_g9_desktop_firmware | - |
| hp | proone_240_g10_firmware | - |
| hp | proone_240_g9_firmware | - |
| hp | proone_440_g3_firmware | - |
| hp | proone_490_g3_firmware | - |
| hp | proone_496_g3_firmware | - |
| hp | z_vr_backpack_g1_workstation_firmware | - |
| hp | zhan_86_pro_g2_microtower_firmware | - |
| hp | zhan_99_pro_g1_microtower_firmware | - |
𝑥
= Vulnerable software versions