
CVE-2022-27541
https://notcve.org/view.php?id=CVE-2022-27541
12 Jun 2023 — Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. • https://support.hp.com/us-en/document/ish_7709808-7709835-16/hpsbhf03835 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •

CVE-2022-27539
https://notcve.org/view.php?id=CVE-2022-27539
12 Jun 2023 — Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. • https://support.hp.com/us-en/document/ish_7709808-7709835-16/hpsbhf03835 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •

CVE-2021-3439
https://notcve.org/view.php?id=CVE-2021-3439
30 Jan 2023 — HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities. • https://support.hp.com/us-en/document/ish_3982318-3982351-16/hpsbhf03735 • CWE-269: Improper Privilege Management •

CVE-2021-3809
https://notcve.org/view.php?id=CVE-2021-3809
30 Jan 2023 — Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities. • https://support.hp.com/us-en/document/ish_6184733-6184761-16/hpsbhf03788 • CWE-269: Improper Privilege Management •

CVE-2021-3808
https://notcve.org/view.php?id=CVE-2021-3808
30 Jan 2023 — Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities. • https://support.hp.com/us-en/document/ish_6184733-6184761-16/hpsbhf03788 • CWE-269: Improper Privilege Management •

CVE-2022-27538
https://notcve.org/view.php?id=CVE-2022-27538
30 Jan 2023 — A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. • https://support.hp.com/us-en/document/ish_7387020-7387107-16/hpsbhf03827 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •

CVE-2021-3661
https://notcve.org/view.php?id=CVE-2021-3661
21 Nov 2022 — A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability. Se ha identificado una posible vulnerabilidad de seguridad en HP Workstation BIOS (firmware UEFI) que puede permitir la ejecución de código arbitrario. HP está lanzando mitigaciones de firmware para la posible vulnerabilidad. • https://support.hp.com/us-en/document/ish_5670997-5671021-16/hpsbhf03770 •

CVE-2022-37018
https://notcve.org/view.php?id=CVE-2022-37018
21 Nov 2022 — A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability. Se ha identificado una vulnerabilidad potencial en el BIOS del sistema para ciertos productos de PC HP que puede permitir la escalada de privilegios y la ejecución de código. HP está lanzando actualizaciones de firmware para mitigar la vulnerabilidad potencial. • https://support.hp.com/us-en/document/ish_7191946-7191970-16/hpsbhf03820 •

CVE-2019-16284
https://notcve.org/view.php?id=CVE-2019-16284
05 Nov 2019 — A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code. A list of affected products and versions are available in https://support.hp.com/rs-en/document/c06456250. Ha sido identificada una potencial vulnerabilidad de seguridad en múltipl... • https://support.hp.com/rs-en/document/c06456250 •

CVE-2016-2243 – HP Security Bulletin HPSBHF03439 1
https://notcve.org/view.php?id=CVE-2016-2243
04 Mar 2016 — Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access. Sure Start en HP Commercial PCs 2015 permite a usuarios locales causar una denegación de servicio (fallo de recuperación de la BIOS) aprovechándose del acceso administrativo. HP has identified a potential security vulnerability with the Sure Start implementation on certain 2015 commercial platforms. This vulnerability could be exploited locally by administrator or... • http://www.securitytracker.com/id/1035193 • CWE-284: Improper Access Control •