CVE-2023-26299
Summary
| CVE | CVE-2023-26299 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-30 16:15:00 UTC |
| Updated | 2023-07-10 18:53:00 UTC |
| Description | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability. |
Risk And Classification
Problem Types: CWE-367
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Hp | 200 G3 | - | All | All | All |
| Operating System | Hp | 200 G3 Firmware | - | All | All | All |
| Hardware | Hp | 200 G4 22 All-in-one | - | All | All | All |
| Operating System | Hp | 200 G4 22 All-in-one Firmware | - | All | All | All |
| Hardware | Hp | 200 Pro G4 22 All-in-one | - | All | All | All |
| Operating System | Hp | 200 Pro G4 22 All-in-one Firmware | - | All | All | All |
| Hardware | Hp | 205 G4 22 All-in-one | - | All | All | All |
| Operating System | Hp | 205 G4 22 All-in-one Firmware | - | All | All | All |
| Hardware | Hp | 205 Pro G4 22 All-in-one | - | All | All | All |
| Operating System | Hp | 205 Pro G4 22 All-in-one Firmware | - | All | All | All |
| Hardware | Hp | 240 G10 | - | All | All | All |
| Operating System | Hp | 240 G10 Firmware | All | All | All | All |
| Hardware | Hp | 245 G6 | - | All | All | All |
| Operating System | Hp | 245 G6 Firmware | All | All | All | All |
| Hardware | Hp | 245 G7 | - | All | All | All |
| Operating System | Hp | 245 G7 Firmware | All | All | All | All |
| Hardware | Hp | 245 G8 | - | All | All | All |
| Operating System | Hp | 245 G8 Firmware | All | All | All | All |
| Hardware | Hp | 247 G8 | - | All | All | All |
| Operating System | Hp | 247 G8 Firmware | All | All | All | All |
| Hardware | Hp | 250 G10 | - | All | All | All |
| Operating System | Hp | 250 G10 Firmware | All | All | All | All |
| Hardware | Hp | 255 G10 | - | All | All | All |
| Operating System | Hp | 255 G10 Firmware | All | All | All | All |
| Hardware | Hp | 260 G4 Desktop Mini | - | All | All | All |
| Operating System | Hp | 260 G4 Desktop Mini Firmware | All | All | All | All |
| Hardware | Hp | 280 G3 | - | All | All | All |
| Operating System | Hp | 280 G3 Firmware | - | All | All | All |
| Hardware | Hp | 280 G4 | - | All | All | All |
| Operating System | Hp | 280 G4 Firmware | - | All | All | All |
| Hardware | Hp | 280 G4 Microtower | - | All | All | All |
| Operating System | Hp | 280 G4 Microtower Firmware | - | All | All | All |
| Hardware | Hp | 280 G5 | - | All | All | All |
| Operating System | Hp | 280 G5 Firmware | - | All | All | All |
| Hardware | Hp | 280 G5 Small Form Factor | - | All | All | All |
| Operating System | Hp | 280 G5 Small Form Factor Firmware | - | All | All | All |
| Hardware | Hp | 280 G6 | - | All | All | All |
| Operating System | Hp | 280 G6 Firmware | - | All | All | All |
| Hardware | Hp | 280 G8 Microtower | - | All | All | All |
| Operating System | Hp | 280 G8 Microtower Firmware | - | All | All | All |
| Hardware | Hp | 280 Pro G3 | - | All | All | All |
| Operating System | Hp | 280 Pro G3 Firmware | - | All | All | All |
| Hardware | Hp | 280 Pro G4 Microtower | - | All | All | All |
| Operating System | Hp | 280 Pro G4 Microtower Firmware | - | All | All | All |
| Hardware | Hp | 280 Pro G5 Small Form Factor | - | All | All | All |
| Operating System | Hp | 280 Pro G5 Small Form Factor Firmware | - | All | All | All |
| Hardware | Hp | 282 G5 | - | All | All | All |
| Operating System | Hp | 282 G5 Firmware | - | All | All | All |
| Hardware | Hp | 282 G6 | - | All | All | All |
| Operating System | Hp | 282 G6 Firmware | - | All | All | All |
| Hardware | Hp | 282 Pro G4 Microtower | - | All | All | All |
| Operating System | Hp | 282 Pro G4 Microtower Firmware | - | All | All | All |
| Hardware | Hp | 288 G5 | - | All | All | All |
| Operating System | Hp | 288 G5 Firmware | - | All | All | All |
| Hardware | Hp | 288 G6 | - | All | All | All |
| Operating System | Hp | 288 G6 Firmware | - | All | All | All |
| Hardware | Hp | 288 Pro G4 Microtower | - | All | All | All |
| Operating System | Hp | 288 Pro G4 Microtower Firmware | - | All | All | All |
| Hardware | Hp | 290 G1 | - | All | All | All |
| Operating System | Hp | 290 G1 Firmware | - | All | All | All |
| Hardware | Hp | 290 G2 | - | All | All | All |
| Operating System | Hp | 290 G2 Firmware | - | All | All | All |
| Hardware | Hp | 290 G2 Microtower | - | All | All | All |
| Operating System | Hp | 290 G2 Microtower Firmware | - | All | All | All |
| Hardware | Hp | 290 G3 | - | All | All | All |
| Operating System | Hp | 290 G3 Firmware | - | All | All | All |
| Hardware | Hp | 290 G3 Small Form Factor | - | All | All | All |
| Operating System | Hp | 290 G3 Small Form Factor Firmware | - | All | All | All |
| Hardware | Hp | 290 G4 | - | All | All | All |
| Operating System | Hp | 290 G4 Firmware | - | All | All | All |
| Hardware | Hp | 349 G7 | - | All | All | All |
| Operating System | Hp | 349 G7 Firmware | All | All | All | All |
| Hardware | Hp | 470 G10 | - | All | All | All |
| Operating System | Hp | 470 G10 Firmware | All | All | All | All |
| Hardware | Hp | 470 G9 | - | All | All | All |
| Operating System | Hp | 470 G9 Firmware | All | All | All | All |
| Hardware | Hp | Desktop Pro G1 Microtower | - | All | All | All |
| Operating System | Hp | Desktop Pro G1 Microtower Firmware | - | All | All | All |
| Hardware | Hp | Proone 240 G10 | - | All | All | All |
| Operating System | Hp | Proone 240 G10 Firmware | - | All | All | All |
| Hardware | Hp | Proone 240 G9 | - | All | All | All |
| Operating System | Hp | Proone 240 G9 Firmware | - | All | All | All |
| Hardware | Hp | Proone 440 G3 | - | All | All | All |
| Operating System | Hp | Proone 440 G3 Firmware | - | All | All | All |
| Hardware | Hp | Proone 490 G3 | - | All | All | All |
| Operating System | Hp | Proone 490 G3 Firmware | - | All | All | All |
| Hardware | Hp | Proone 496 G3 | - | All | All | All |
| Operating System | Hp | Proone 496 G3 Firmware | - | All | All | All |
| Hardware | Hp | Pro Small Form Factor 280 G9 Desktop | - | All | All | All |
| Operating System | Hp | Pro Small Form Factor 280 G9 Desktop Firmware | - | All | All | All |
| Hardware | Hp | Pro Small Form Factor 290 G9 Desktop | - | All | All | All |
| Operating System | Hp | Pro Small Form Factor 290 G9 Desktop Firmware | - | All | All | All |
| Hardware | Hp | Pro Small Form Factor Zhan 66 G9 Desktop | - | All | All | All |
| Operating System | Hp | Pro Small Form Factor Zhan 66 G9 Desktop Firmware | - | All | All | All |
| Hardware | Hp | Pro Tower 200 G9 Desktop | - | All | All | All |
| Operating System | Hp | Pro Tower 200 G9 Desktop Firmware | - | All | All | All |
| Hardware | Hp | Pro Tower 280 G9 Desktop | - | All | All | All |
| Operating System | Hp | Pro Tower 280 G9 Desktop Firmware | - | All | All | All |
| Hardware | Hp | Pro Tower 290 G9 Desktop | - | All | All | All |
| Operating System | Hp | Pro Tower 290 G9 Desktop Firmware | - | All | All | All |
| Hardware | Hp | Pro Tower Zhan 99 G9 Desktop | - | All | All | All |
| Operating System | Hp | Pro Tower Zhan 99 G9 Desktop Firmware | - | All | All | All |
| Hardware | Hp | T430 | - | All | All | All |
| Operating System | Hp | T430 Firmware | All | All | All | All |
| Hardware | Hp | T628 | - | All | All | All |
| Operating System | Hp | T628 Firmware | All | All | All | All |
| Hardware | Hp | Vr Backpack G2 | - | All | All | All |
| Operating System | Hp | Vr Backpack G2 Firmware | All | All | All | All |
| Hardware | Hp | Zhan 86 Pro G2 Microtower | - | All | All | All |
| Operating System | Hp | Zhan 86 Pro G2 Microtower Firmware | - | All | All | All |
| Hardware | Hp | Zhan 99 G2 | - | All | All | All |
| Operating System | Hp | Zhan 99 G2 Firmware | All | All | All | All |
| Hardware | Hp | Zhan 99 G4 | - | All | All | All |
| Operating System | Hp | Zhan 99 G4 Firmware | All | All | All | All |
| Hardware | Hp | Zhan 99 Pro G1 Microtower | - | All | All | All |
| Operating System | Hp | Zhan 99 Pro G1 Microtower Firmware | - | All | All | All |
| Hardware | Hp | Z Vr Backpack G1 Workstation | - | All | All | All |
| Operating System | Hp | Z Vr Backpack G1 Workstation Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| AMI UEFI Firmware June 2023 Security Update (TOCTOU) | HP® Customer Support | MISC | support.hp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.