CVE-2019-6321 describes a high-severity vulnerability in certain HP Workstation BIOS (UEFI Firmware) versions, specifically affecting models like the Z4, Z6, and Z8 G4 series. This flaw allows for runtime BIOS code tampering if the Trusted Platform Module (TPM) is disabled, which is the default state for some affected workstations. The vulnerability has a CVSS score of 7.2, indicating a high potential for impact with complete compromise of confidentiality, integrity, and availability, and can be exploited remotely with high privileges and low attack complexity. Despite its severity, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is there evidence of active exploitation or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.70CPE matchmatch criteria | cpe:2.3:o:hp:z4_g4_workstation_firmware:*:*:*:*:*:*:*:* | ||
< 1.70CPE matchmatch criteria | cpe:2.3:o:hp:z4_g4_core-x_workstation_firmware:*:*:*:*:*:*:*:* | ||
< 1.71CPE matchmatch criteria | cpe:2.3:o:hp:z6_g4_workstation_firmware:*:*:*:*:*:*:*:* | ||
< 1.71CPE matchmatch criteria | cpe:2.3:o:hp:z8_g4_workstation_firmware:*:*:*:*:*:*:*:* | ||
< 1.70CPE matchmatch criteria | cpe:2.3:o:hp:z4_g4_workstation_firmware:*:*:*:*:*:linux:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.