CVE-2024-5477CWE-1256

A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escalation of privilege, arbitrary code…

High · published August 13, 2025

CVSS v4.0
7.3
EPSS
0%
Percentile
6.4
In the wild
Unconfirmed
What it is

A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escalation of privilege, arbitrary code execution, denial of service, or information disclosure via a physical attack that requires specialized equipment and knowledge. HP is releasing firmware mitigation for the potential vulnerability.

The record
Technical detail
CVSS v4.0
7.3 · HIGH
Vector
CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS
0.00169 · 6.4th percentile
Weakness
CWE-1256 · Improper Restriction of Software Interfaces to Hardware Features
Published
2025-08-13T17:47Z
EPSS history
Timeline
  • 13 AUG 17:47Z
    A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escalation of privilege, arbitrary code…
    cvelistv5