CVE-2021-39299
published 2022-02-16CVE-2021-39299: Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code…
PriorityP345high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.42%
34.4th percentile
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
Affected
183 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | 260_g3_desktop_mini_pc_firmware | <= 2.17.00 | — |
| hp | elite_dragonfly_firmware | < 01.12.00 | 01.12.00 |
| hp | elite_dragonfly_g2_firmware | < 01.08.00 | 01.08.00 |
| hp | elite_dragonfly_max_firmware | < 01.08.00 | 01.08.00 |
| hp | elite_x2_1013_g3_firmware | < 01.19.00 | 01.19.00 |
| hp | elite_x2_g4_firmware | < 01.12.00 | 01.12.00 |
| hp | elite_x2_g8_tablet_firmware | < 01.08.00 | 01.08.00 |
| hp | elitebook_1050_g1_firmware | < 01.19.00 | 01.19.00 |
| hp | elitebook_830_g5_firmware | < 01.19.00 | 01.19.00 |
| hp | elitebook_830_g6_firmware | < 01.12.00 | 01.12.00 |
| hp | elitebook_830_g7_firmware | < 01.08.00 | 01.08.00 |
| hp | elitebook_830_g8_firmware | < 01.08.00 | 01.08.00 |
| hp | elitebook_836_g5_firmware | < 01.19.00 | 01.19.00 |
| hp | elitebook_836_g6_firmware | < 01.12.00 | 01.12.00 |
| hp | elitebook_840_aero_g8_firmware | < 01.08.00 | 01.08.00 |
| hp | elitebook_840_g5_firmware | < 01.19.00 | 01.19.00 |
| hp | elitebook_840_g5_healthcare_edition_firmware | < 01.19.00 | 01.19.00 |
| hp | elitebook_840_g6_firmware | < 01.12.00 | 01.12.00 |
| hp | elitebook_840_g6_healthcare_edition_firmware | < 01.12.00 | 01.12.00 |
| hp | elitebook_840_g7_firmware | < 01.08.00 | 01.08.00 |
| hp | elitebook_840_g8_firmware | < 01.08.00 | 01.08.00 |
| hp | elitebook_840r_g4_firmware | < 01.19.00 | 01.19.00 |
| hp | elitebook_846_g5_firmware | < 01.19.00 | 01.19.00 |
| hp | elitebook_850_g5_firmware | < 01.19.00 | 01.19.00 |
| hp | elitebook_850_g6_firmware | < 01.12.00 | 01.12.00 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-16
Published