Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-5477

23
FAUCET Score

CVE-2024-5477 is a high-severity vulnerability affecting the System BIOS of certain HP PC products. This flaw could enable a physical attacker, using specialized equipment and knowledge, to achieve escalation of privilege, arbitrary code execution, denial of service, or information disclosure. The CVSS score of 7.3 reflects the high impact on confidentiality, integrity, and availability, despite requiring physical access and high attack complexity. HP is releasing firmware mitigations. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
HP Inc.Certain HP PC Products
See HP Security Bulletin reference for affected versions.CNA affecteddefault unknown

CVSS Data

CVSS version used by this source: 4.0

7.3HIGH

CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
PHYSICAL
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 0th percentile among its peer group of 10 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.3 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gcppatch availablevia llm_extracted
View patch

Vendor Advisories (1)

gcpllm-gcp-52c17fa0f40ab052HIGH

HP BIOS Flash Protection Security Update

Aug 12, 2025

References

support.hp.com / us-en/document/ish_12878449-12878471-16/hpsbhf04043