CVE-2019-6321: Critical severity hp z4 workstation vulnerability
HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is disabled by default.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this HP BIOS security vulnerability?
The vulnerability ID for this HP BIOS security vulnerability is CVE-2019-6321.
What is the severity of CVE-2019-6321?
The severity of CVE-2019-6321 is critical, with a severity value of 7.2.
Which versions of HP Workstation BIOS (UEFI Firmware) are affected by this vulnerability?
This vulnerability affects some versions of HP Workstation BIOS (UEFI Firmware), including Hp Z4 G4 Workstation Firmware (up to version 1.70), Hp Z4 G4 Core-x Workstation Firmware (up to version 1.70), Hp Z6 G4 Workstation Firmware (up to version 1.71), and Hp Z8 G4 Workstation Firmware (up to version 1.71).
What is the impact of this vulnerability?
The impact of this vulnerability is that the runtime BIOS code could be tampered with if the TPM is disabled.
How can I fix CVE-2019-6321?
To fix CVE-2019-6321, it is recommended to enable the TPM (Trusted Platform Module) on the affected HP workstations.