CVE-2017-2751

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
03/10/2018
Last modified:
03/10/2019

Description

A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hp:hp_240_g1_firmware:*:*:*:*:*:*:*:* f.48 (excluding)
cpe:2.3:h:hp:hp_240_g1:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:hp_245_g1_firmware:*:*:*:*:*:*:*:* f.48 (excluding)
cpe:2.3:h:hp:hp_245_g1:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:hp_1000-1300_firmware:*:*:*:*:*:*:*:* f.48 (excluding)
cpe:2.3:h:hp:hp_1000-1300:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:hp_250_g1_notebook_pc_firmware:*:*:*:*:*:*:*:* f.47 (excluding)
cpe:2.3:h:hp:hp_250_g1_notebook_pc:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:hp_255_g1_notebook_pc_firmware:*:*:*:*:*:*:*:* f.47 (excluding)
cpe:2.3:h:hp:hp_255_g1_notebook_pc:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:hp_envy_15-j000_firmware:*:*:*:*:*:*:*:* f.22 (excluding)
cpe:2.3:h:hp:hp_envy_15-j000:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:hp_envy_15-j100_firmware:*:*:*:*:*:*:*:* f.71 (excluding)
cpe:2.3:h:hp:hp_envy_15-j100:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:hp_pavilion_15-n000_firmware:*:*:*:*:*:*:*:* f.72 (excluding)


References to Advisories, Solutions, and Tools