CVE-2023-5409: Medium severity hp t430 thin client firmware vulnerability
HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack, allowing an untrusted source to tamper with the system firmware using a publicly disclosed private key. HP is providing recommended guidance for customers to reduce exposure to the potential vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2023-5409.
Which HP models are affected by this vulnerability?
HP t430 and t638 Thin Client PCs are affected by this vulnerability.
What type of attack is possible with this vulnerability?
This vulnerability can be exploited through a physical attack.
How can an attacker tamper with the system firmware?
An attacker can tamper with the system firmware using a publicly disclosed private key.
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 6.8.
Where can I find guidance from HP on this vulnerability?
You can find guidance from HP on this vulnerability at the following link: [HP Support Document](https://support.hp.com/us-en/document/ish_9441200-9441233-16)