CVE-2021-3661: Code Injection
A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-3661?
CVE-2021-3661 refers to a potential security vulnerability identified in certain HP Workstation BIOS (UEFI firmware) that may allow arbitrary code execution.
Which HP Workstations are affected by CVE-2021-3661?
The HP Z1 All-in-one G3, HP Z2 Mini G3, HP Z2 Mini G4, HP Z2 Mini G5, HP Z2 Small Form Factor G4, HP Z2 Small Form Factor G5, HP Z2 Small Form Factor G8, HP Z2 Tower G4, HP Z2 Tower G5, HP Z2 Tower G8, HP Z238 Microtower, HP Z240 Small Form Factor, HP Z240 Tower, HP Z4 G4, HP Z440, HP Z6 G4, HP Z640, HP Z8 G4, and HP Z840 are affected by CVE-2021-3661.
What is the severity of CVE-2021-3661?
CVE-2021-3661 has a severity rating of 8.4, which is considered high.
How can I mitigate the vulnerability in my HP Workstation?
HP is releasing firmware mitigations for the vulnerability. Please refer to the HP support document for more information on the mitigation steps.
Where can I find more information about CVE-2021-3661?
You can find more information about CVE-2021-3661 in the HP support document available at the provided reference link.