Home

Description

A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escalation of privilege, arbitrary code execution, denial of service, or information disclosure via a physical attack that requires specialized equipment and knowledge. HP is releasing firmware mitigation for the potential vulnerability.

PUBLISHED Reserved 2024-05-29 | Published 2025-08-13 | Updated 2025-08-13 | Assigner hp




HIGH: 7.3CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-1256 - Improper Restriction of Software and Firmware Updates

Product status

Default status
unknown

See HP Security Bulletin reference for affected versions.
affected

References

support.hp.com/...ument/ish_12878449-12878471-16/hpsbhf04043

cve.org (CVE-2024-5477)

nvd.nist.gov (CVE-2024-5477)

Download JSON