CVE-2021-39298
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/02/2022
Last modified:
24/02/2026
Description
A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:hp:z1_entry_tower_g5_workstation_firmware:*:*:*:*:*:*:*:* | 02.12.00 (excluding) | |
| cpe:2.3:h:hp:z1_entry_tower_g5_workstation:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:z1_entry_tower_g6_workstation_firmware:*:*:*:*:*:*:*:* | 02.10.00 (excluding) | |
| cpe:2.3:h:hp:z1_entry_tower_g6_workstation:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:z1_g8_tower_desktop_pc_firmware:*:*:*:*:*:*:*:* | 02.07.00 (excluding) | |
| cpe:2.3:h:hp:z1_g8_tower_desktop_pc:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:z4_g4_workstation_\(core-x\)_firmware:*:*:*:*:*:linux_kernel:*:* | 02.75 (excluding) | |
| cpe:2.3:o:hp:z4_g4_workstation_\(core-x\)_firmware:*:*:*:*:*:windows_10:*:* | 02.75 (excluding) | |
| cpe:2.3:o:hp:z4_g4_workstation_\(core-x\)_firmware:*:*:*:*:*:windows_7:*:* | 02.75 (excluding) | |
| cpe:2.3:h:hp:z4_g4_workstation_\(core-x\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:z4_g4_workstation_\(xeon_w\)_firmware:*:*:*:*:*:linux_kernel:*:* | 02.75 (excluding) | |
| cpe:2.3:o:hp:z4_g4_workstation_\(xeon_w\)_firmware:*:*:*:*:*:windows_10:*:* | 02.75 (excluding) | |
| cpe:2.3:o:hp:z4_g4_workstation_\(xeon_w\)_firmware:*:*:*:*:*:windows_7:*:* | 02.75 (excluding) | |
| cpe:2.3:h:hp:z4_g4_workstation_\(xeon_w\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:z6_g4_workstation_firmware:*:*:*:*:*:linux_kernel:*:* | 02.75 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



