Medium severity4.6NVD Advisory· Published Oct 3, 2018· Updated Jun 17, 2026
CVE-2017-2751
CVE-2017-2751
Description
A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.
Affected products
35- HP Inc./HP 240 G1 Notebook PC and certain other consumer notebooksv5Range: F.22 and other firmware versions
- cpe:2.3:o:hp:hp_250_g1_notebook_pc_firmware:*:*:*:*:*:*:*:*Range: <f.47
- cpe:2.3:o:hp:hp_255_g1_notebook_pc_firmware:*:*:*:*:*:*:*:*Range: <f.47
- cpe:2.3:o:hp:hp_envy_15-j000_firmware:*:*:*:*:*:*:*:*Range: <f.22
- cpe:2.3:o:hp:hp_envy_15-j100_firmware:*:*:*:*:*:*:*:*Range: <f.71
- cpe:2.3:o:hp:hp_pavilion_15-n000_firmware:*:*:*:*:*:*:*:*Range: <f.72
- cpe:2.3:o:hp:hp_envy_17_j100_firmware:*:*:*:*:*:*:*:*Range: <f.71
- cpe:2.3:o:hp:hp_envy_17-j100_leap_motion_se_firmware:*:*:*:*:*:*:*:*Range: <f.71
- cpe:2.3:o:hp:hp_split_13-g200_firmware:*:*:*:*:*:*:*:*Range: <f.25
- cpe:2.3:o:hp:hp_pavilion_14-n000_firmware:*:*:*:*:*:*:*:*Range: <f.72
- cpe:2.3:o:hp:hp_envy_14-k100_firmware:*:*:*:*:*:*:*:*Range: <f.22
- cpe:2.3:o:hp:hp_spectre_x2_13-smb_pro_firmware:*:*:*:*:*:*:*:*Range: <f.25
- cpe:2.3:o:hp:hp_spectre_13-h200_firmware:*:*:*:*:*:*:*:*Range: <f.25
- cpe:2.3:o:hp:hp_pavilion_15-n200_firmware:*:*:*:*:*:*:*:*Range: <f.72
- cpe:2.3:o:hp:hp_pavilion_15-n300_firmware:*:*:*:*:*:*:*:*Range: <f.72
- cpe:2.3:o:hp:hp_envy_m6-n000_firmware:*:*:*:*:*:*:*:*Range: <f.26
- cpe:2.3:o:hp:hp_pavilion_11-n000_firmware:*:*:*:*:*:*:*:*Range: <f.2e
- cpe:2.3:o:hp:hp_pavilion_10-f000_firmware:*:*:*:*:*:*:*:*Range: <f.0e
- cpe:2.3:o:hp:compaq_cq45-900_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hp:compaq_14-h000_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hp:compaq_14-s000_firmware:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- support.hp.com/us-en/document/c05913581nvdVendor Advisory
News mentions
0No linked articles in our index yet.