CVE-2017-2751: Medium severity hp 240 g1 firmware vulnerability

Published Oct 3, 2018
·
Updated

A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.

Affected Software

68 affected components
HP Hp 240 G1 Firmware<f.48
HP Hp 240 G1
HP Hp 245 G1 Firmware<f.48
HP Hp 245 G1
HP Hp 1000-1300 Firmware<f.48
HP Hp 1000-1300
HP Hp 250 G1 Notebook Pc Firmware<f.47
HP Hp 250 G1 Notebook Pc
HP Hp 255 G1 Notebook Pc Firmware<f.47
HP Hp 255 G1 Notebook Pc
HP Hp Envy 15-j000 Firmware<f.22
HP Hp Envy 15-j000
HP Hp Envy 15-j100 Firmware<f.71
HP Hp Envy 15-j100
HP Hp Pavilion 15-n000 Firmware<f.72
HP Hp Pavilion 15-n000
HP Hp 246 Firmware<f.04
HP Hp 246
HP Hp 455 Firmware<f.08
HP Hp 455
HP Hp Envy 17 J100 Firmware<f.71
HP Hp Envy 17 J100
HP Hp Envy 17-j100 Leap Motion Se Firmware<f.71
HP Hp Envy 17-j100 Leap Motion Se
HP Hp Split 13-g200 Firmware<f.25
HP Hp Split 13-g200
HP Hp Envy 100 Firmware<f.22
HP Hp Envy 100
HP Hp Pavilion 14-n000 Firmware<f.72
HP Hp Pavilion 14-n000
HP Hp Envy 14-k100 Firmware<f.22
HP Hp Envy 14-k100
HP Hp Spectre X2 13-smb Pro Firmware<f.25
HP Hp Spectre X2 13-smb Pro
HP Hp Spectre 13-h200 Firmware<f.25
HP Hp Spectre 13-h200
HP Hp Pavilion 15-n200 Firmware<f.72
HP Hp Pavilion 15-n200
HP Hp Pavilion 15-n300 Firmware<f.72
HP Hp Pavilion 15-n300
HP Hp Envy M6-n000 Firmware<f.26
HP Hp Envy M6-n000
HP Hp 255 G3 Firmware<f.45
HP Hp 255 G3
HP Hp 14-g000 Firmware<f.45
HP Hp 14-g000
HP Hp Pavilion 11-n000 Firmware<f.2e
HP Hp Pavilion 11-n000
HP Hp 15-r000 Firmware<f.43
HP Hp 15-r000
HP Hp 15-r500 Firmware<f.43
HP Hp 15-r500
HP Hp Pavilion 10-f000 Firmware<f.0e
HP Hp Pavilion 10-f000
HP Hp G14-a000 Firmware<f.06
HP Hp G14-a000
HP Hp 14-r000 Firmware<f.43
HP Hp 14-r000
HP Hp 240 G3 Firmware<f.43
HP Hp 240 G3
HP Hp 246 G3 Firmware<f.43
HP Hp 246 G3
HP Compaq Cq45-900 Firmware
HP Compaq Cq45-900
HP Compaq 14-h000 Firmware
HP Compaq 14-h000
HP Compaq 14-s000 Firmware
HP Compaq 14-s000

Event History

Oct 3, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-2751?

CVE-2017-2751 is considered a medium severity vulnerability as it allows unauthorized access to stored BIOS passwords.

2

How do I fix CVE-2017-2751?

To fix CVE-2017-2751, update the BIOS firmware to the latest version provided by HP that addresses this vulnerability.

3

Which HP notebooks are affected by CVE-2017-2751?

CVE-2017-2751 affects several HP consumer notebooks launched in early 2014 with specific firmware versions, including HP 240 G1, 245 G1, and Envy models.

4

What is the impact of CVE-2017-2751 on system security?

The impact of CVE-2017-2751 is significant, as it potentially allows attackers to extract BIOS passwords, compromising the security of the affected systems.

5

How can I determine if my firmware version is vulnerable to CVE-2017-2751?

You can determine if your firmware version is vulnerable to CVE-2017-2751 by checking the BIOS version against the list of affected versions provided by HP.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203