HIGH · 8.8

CVE-2021-39299

Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

Vulnerability Description

Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HpElite Dragonfly Firmware< 01.12.00
HpElite Dragonfly-
HpElite Dragonfly G2 Firmware< 01.08.00
HpElite Dragonfly G2-
HpElite Dragonfly Max Firmware< 01.08.00
HpElite Dragonfly Max-
HpElite X2 1013 G3 Firmware< 01.19.00
HpElite X2 1013 G3-
HpElite X2 G4 Firmware< 01.12.00
HpElite X2 G4-
HpElite X2 G8 Tablet Firmware< 01.08.00
HpElite X2 G8 Tablet-
HpElitebook 1050 G1 Firmware< 01.19.00
HpElitebook 1050 G1-
HpElitebook 830 G5 Firmware< 01.19.00
HpElitebook 830 G5-
HpElitebook 830 G6 Firmware< 01.12.00
HpElitebook 830 G6-
HpElitebook 830 G7 Firmware< 01.08.00
HpElitebook 830 G7-

References

FAQ

What is CVE-2021-39299?

CVE-2021-39299 is a vulnerability with a CVSS score of 8.8 (HIGH). Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

How severe is CVE-2021-39299?

CVE-2021-39299 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-39299?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Elite Dragonfly Firmware, Hp Elite Dragonfly, Hp Elite Dragonfly G2 Firmware, Hp Elite Dragonfly G2, Hp Elite Dragonfly Max Firmware.