V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2017-2751
CVE
MediumConfirmedExploit available

A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password w…

CVSS
4.6
Medium
EPSS
0.04
p89
Published
2017-01-01
Updated
2017-01-01
Description

A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.

Tags · CWE
CWE-522
CAPEC-50
CAPEC-102
CAPEC-474
CAPEC-509
CAPEC-551
CAPEC-555
CAPEC-560
CAPEC-561
CAPEC-600
CAPEC-644
CAPEC-645
CAPEC-652
CAPEC-653
Affected products
Compaq_14-h000_firmwareCompaq_14-s000_firmwareCompaq_cq45-900_firmwareHp_1000-1300_firmwareHp_14-g000_firmwareHp_14-r000_firmwareHp_15-r000_firmwareHp_15-r500_firmwareHp_240_g1_firmwareHp_240_g3_firmwareHp_245_g1_firmwareHp_246_firmwareHp_246_g3_firmwareHp_250_g1_notebook_pc_firmwareHp_255_g1_notebook_pc_firmwareHp_255_g3_firmwareHp_455_firmwareHp_envy_100_firmwareHp_envy_14-k100_firmwareHp_envy_15-j000_firmware
CVSS vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: P
Physical (P)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.044 · p89
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-555 · CWE-522
└ via CAPEC-561 · CWE-522
└ via CAPEC-560 · CWE-522
└ via CAPEC-600 · CWE-522
└ via CAPEC-555 · CWE-522
└ via CAPEC-555 · CWE-522
└ via CAPEC-551 · CWE-522
└ via CAPEC-644 · CWE-522
└ via CAPEC-645 · CWE-522
└ via CAPEC-474 · CWE-522
└ via CAPEC-652 · CWE-522
└ via CAPEC-509 · CWE-522
Known exploits — Сканер-ВС
CVE-2017-2751
github-poc · https://github.com/BaderSZ/CVE-2017-2751
Enterprise
Affected software
ProductVendorStatus
compaq_14-h000_firmware*Tracked
compaq_14-s000_firmware*Tracked
compaq_cq45-900_firmware*Tracked
hp_1000-1300_firmware*Tracked
hp_14-g000_firmware*Tracked
hp_14-r000_firmware*Tracked
hp_15-r000_firmware*Tracked
hp_15-r500_firmware*Tracked
hp_240_g1_firmware*Tracked
hp_240_g3_firmware*Tracked
hp_245_g1_firmware*Tracked
hp_246_firmware*Tracked
hp_246_g3_firmware*Tracked
hp_250_g1_notebook_pc_firmware*Tracked
hp_255_g1_notebook_pc_firmware*Tracked
hp_255_g3_firmware*Tracked
hp_455_firmware*Tracked
hp_envy_100_firmware*Tracked
hp_envy_14-k100_firmware*Tracked
hp_envy_15-j000_firmware*Tracked
Source databases
CVE