CVE-2021-39297High· 8.8▾ TwilightPotential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
7.8 → 8.8
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
260_g3_desktop_mini_pc_firmware <= 2.17.00elitedesk_800_35w_g4_desktop_mini_pc_firmware <= 2.18.00elitedesk_800_65w_g4_desktop_mini_pc_firmware <= 2.18.00elitedesk_800_95w_g4_desktop_mini_pc_firmware <= 2.18.00elitedesk_800_g4_small_form_factor_pc_firmware <= 2.18.00elitedesk_800_g4_tower_pc_firmware <= 2.18.00elitedesk_800_g4_workstation_edition_firmware <= 2.18.00elitedesk_800_g5_desktop_mini_pc_firmware <= 2.12.00elitedesk_800_g5_small_form_factor_pc_firmware <= 2.12.00elitedesk_800_g5_tower_pc_firmware <= 2.12.00elitedesk_800_g6_desktop_mini_pc_firmware <= 2.10.00elitedesk_800_g6_small_form_factor_pc_firmware <= 2.10.00elitedesk_800_g6_tower_pc_firmware <= 2.10.00elitedesk_800_g8_desktop_mini_pc_firmware <= 2.07.00elitedesk_800_g8_small_form_factor_pc_firmware <= 2.07.00elitedesk_800_g8_tower_pc_firmware <= 2.07.00elitedesk_805_g6_desktop_mini_pc_firmware <= 2.07.00elitedesk_805_g6_small_form_factor_pc_firmware <= 2.07.00elitedesk_805_g8_desktop_mini_pc_firmware <= 2.03.00elitedesk_805_g8_small_form_factor_pc_firmware <= 2.03.00elitedesk_880_g4_tower_pc_firmware <= 2.18.00elitedesk_880_g5_tower_pc_firmware <= 2.12.00elitedesk_880_g6_tower_pc_firmware <= 2.10.00elitedesk_880_g8_tower_pc_firmware <= 2.07.00eliteone_1000_g2_23.8-in_all-in-one_business_pc_firmware <= 2.18.00eliteone_1000_g2_23.8-in_touch_all-in-one_business_pc_firmware <= 2.18.00eliteone_1000_g2_27-in_4k_uhd_all-in-one_business_pc_firmware <= 2.18.00eliteone_1000_g2_34-in_curved_all-in-one_business_pc_firmware <= 2.18.00eliteone_800_g4_23.8-in_healthcare_edition_all-in-one_business_pc_firmware <= 2.18.00eliteone_800_g4_23.8-inch_non-touch_all-in-one_pc_firmware <= 2.18.00eliteone_800_g4_23.8-inch_non-touch_gpu_all-in-one_pc_firmware <= 2.18.00eliteone_800_g4_23.8-inch_touch_all-in-one_pc_firmware <= 2.18.00eliteone_800_g4_23.8-inch_touch_gpu_all-in-one_pc_firmware <= 2.18.00eliteone_800_g5_23.8-in_healthcare_edition_all-in-one_firmware <= 2.12.00eliteone_800_g5_23.8-inch_all-in-one_firmware <= 2.12.00eliteone_800_g6_24_all-in-one_pc_firmware <= 2.10.00eliteone_800_g6_27_all-in-one_pc_firmware <= 2.10.00eliteone_800_g8_24_all-in-one_pc_firmware <= 2.07.00eliteone_800_g8_27_all-in-one_pc_firmware <= 2.07.00prodesk_400_g4_desktop_mini_pc_firmware <= 2.18.00prodesk_400_g5_desktop_mini_pc_firmware <= 2.12.00prodesk_400_g5_microtower_pc_firmware <= 2.18.00prodesk_400_g5_small_form_factor_pc_firmware <= 2.18.00prodesk_400_g6_desktop_mini_pc_firmware <= 2.10.00prodesk_400_g6_microtower_pc_firmware <= 2.12.00prodesk_400_g6_small_form_factor_pc_firmware <= 2.12.00prodesk_400_g7_microtower_pc_firmware <= 2.10.00prodesk_400_g7_small_form_factor_pc_firmware <= 2.10.00prodesk_405_g8_desktop_mini_pc_firmware <= 2.03.00prodesk_405_g8_small_form_factor_pc_firmware <= 2.03.00prodesk_480_g5_microtower_pc_firmware <= 2.18.00prodesk_480_g6_microtower_pc_firmware <= 2.12.00prodesk_480_g7_pci_microtower_pc_firmware <= 2.10.00prodesk_600_g4_desktop_mini_pc_firmware <= 2.18.00prodesk_600_g4_microtower_pc_firmware <= 2.18.00prodesk_600_g4_microtower_pc(with_pci_slot)_firmware <= 2.18.00prodesk_600_g4_small_form_factor_pc_firmware <= 2.18.00prodesk_600_g5_desktop_mini_pc_firmware <= 2.12.00prodesk_600_g5_microtower_pc_firmware <= 2.12.00prodesk_600_g5_microtower_pc(with_pci_slot)_firmware <= 2.12.00prodesk_600_g5_small_form_factor_pc_firmware <= 2.12.00prodesk_600_g6_desktop_mini_pc_firmware <= 2.10.00prodesk_600_g6_microtower_pc_firmware <= 2.10.00prodesk_600_g6_small_form_factor_pc_firmware <= 2.10.00prodesk_680_g4_microtower_pc_firmware <= 2.18.00prodesk_680_g4_microtower_pc(with_pci_slot)_firmware <= 2.18.00prodesk_680_g6_pci_microtower_pc_firmware <= 2.10.00proone_400_g4_20-inch_non-touch_all-in-one_business_pc_firmware <= 2.18.00proone_400_g4_23.8-inch_non-touch_all-in-one_business_pc_firmware <= 2.18.00proone_400_g5_20-inch_all-in-one_business_pc_firmware <= 2.12.00proone_400_g5_23.8-inch_all-in-one_business_pc_firmware <= 2.12.00proone_400_g6_20_all-in-one_pc_firmware <= 2.10.00proone_400_g6_24_all-in-one_pc_firmware <= 2.10.00proone_440_g4_23.8-inch_non-touch_all-in-one_business_pc_firmware <= 2.18.00proone_440_g5_23.8-in_all-in-one_business_pc_firmware <= 2.12.00proone_440_g6_24_all-in-one_pc_firmware <= 2.10.00proone_600_g4_21.5-inch_touch_all-in-one_business_pc_firmware <= 2.18.00proone_600_g5_21.5-in_all-in-one_business_pc_firmware <= 2.12.00proone_600_g6_22_all-in-one_pc_firmware <= 2.10.00zhan_66_pro_g3_22_all-in-one_pc_firmware <= 2.10.00zhan_66_pro_g3_24_all-in-one_pc_firmware <= 2.10.00z1_entry_tower_g5_workstation_firmware < 02.12.00z1_entry_tower_g6_workstation_firmware < 02.10.00z1_g8_tower_desktop_pc_firmware < 02.07.00z4_g4_workstation_(core-x)_firmware < 02.75z4_g4_workstation_(xeon_w)_firmware < 02.75z6_g4_workstation_firmware < 02.75z8_g4_workstation_firmware < 02.75engage_flex_mini_retail_system_firmware < 02.10.00mp9_g4_retail_system_firmware < 02.18.00elite_dragonfly_firmware < 01.12.00elite_dragonfly_g2_firmware < 01.08.00elite_dragonfly_max_firmware < 01.08.00elite_x2_1013_g3_firmware < 01.19.00elite_x2_g4_firmware < 01.12.00elite_x2_g8_tablet_firmware < 01.08.00elitebook_1050_g1_firmware < 01.19.00elitebook_830_g5_firmware < 01.19.00elitebook_830_g6_firmware < 01.12.00elitebook_830_g7_firmware < 01.08.00Upgrade past the affected range:
z1_entry_tower_g5_workstation_firmware 02.12.00z1_entry_tower_g6_workstation_firmware 02.10.00z1_g8_tower_desktop_pc_firmware 02.07.00z4_g4_workstation_(core-x)_firmware 02.75z4_g4_workstation_(xeon_w)_firmware 02.75z6_g4_workstation_firmware 02.75z8_g4_workstation_firmware 02.75engage_flex_mini_retail_system_firmware 02.10.00mp9_g4_retail_system_firmware 02.18.00elite_dragonfly_firmware 01.12.00elite_dragonfly_g2_firmware 01.08.00elite_dragonfly_max_firmware 01.08.00elite_x2_1013_g3_firmware 01.19.00elite_x2_g4_firmware 01.12.00elite_x2_g8_tablet_firmware 01.08.00elitebook_1050_g1_firmware 01.19.00elitebook_830_g5_firmware 01.19.00elitebook_830_g6_firmware 01.12.00elitebook_830_g7_firmware 01.08.00Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-39300High· 8.8Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
CVE-2021-39301High· 8.8Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
CVE-2021-39299High· 8.8Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
CVE-2021-39298High· 8.8A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security…
CVE-2016-3092High· 7.5The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial…
CVE-2026-91097Critical· 9.8HP has identified and remediated multiple externally reported vulnerabilities within HPLIP