CVE-2023-26299: A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system...

0.0 CVSS

Description

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.

Classification

CVE ID: CVE-2023-26299

CVSS Base Severity: LOW

CVSS Base Score: 0.0

Affected Products

Vendor: HP Inc.

Product: HP PC products using AMI UEFI Firmware

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 14.88% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://support.hp.com/us-en/document/ish_8642715-8642746-16/hpsbhf03850

Timeline