MEDIUM · 4.6

CVE-2017-2751

A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. T...

Vulnerability Description

A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.

CVSS Score

4.6

MEDIUM

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HpHp 240 G1 Firmware< f.48
HpHp 240 G1-
HpHp 245 G1 Firmware< f.48
HpHp 245 G1-
HpHp 1000-1300 Firmware< f.48
HpHp 1000-1300-
HpHp 250 G1 Notebook Pc Firmware< f.47
HpHp 250 G1 Notebook Pc-
HpHp 255 G1 Notebook Pc Firmware< f.47
HpHp 255 G1 Notebook Pc-
HpHp Envy 15-J000 Firmware< f.22
HpHp Envy 15-J000-
HpHp Envy 15-J100 Firmware< f.71
HpHp Envy 15-J100-
HpHp Pavilion 15-N000 Firmware< f.72
HpHp Pavilion 15-N000-
HpHp 246 Firmware< f.04
HpHp 246-
HpHp 455 Firmware< f.08
HpHp 455-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-2751?

CVE-2017-2751 is a vulnerability with a CVSS score of 4.6 (MEDIUM). A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. T...

How severe is CVE-2017-2751?

CVE-2017-2751 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-2751?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Hp 240 G1 Firmware, Hp Hp 240 G1, Hp Hp 245 G1 Firmware, Hp Hp 245 G1, Hp Hp 1000-1300 Firmware.