High severity8.4NVD Advisory· Published Dec 12, 2022· Updated Jun 17, 2026
CVE-2021-3661
CVE-2021-3661
Description
A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.
Affected products
22- HP Inc./HP Workstation BIOSv5Range: See HP Security Bulletin reference for affected versions.
- cpe:2.3:o:hp:z1_all-in-one_g3_firmware:01.31:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z2_mini_g3_firmware:01.83:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z2_mini_g4_firmware:01.08.01:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z2_mini_g5_firmware:01.03.00_rev_a:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z2_small_form_factor_g4_firmware:01.08.01:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z2_small_form_factor_g5_firmware:01.03.00_rev_a:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z2_small_form_factor_g8_firmware:01.03.00_rev_a:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z2_tower_g4_firmware:01.08.01:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z2_tower_g5_firmware:01.03.00_rev_a:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z2_tower_g8_firmware:01.03.00_rev_a:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z238_microtower_firmware:01.83:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z240_small_form_factor_firmware:01.83:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z240_tower_firmware:01.83:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z4_g4_firmware:02.75:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z440_firmware:2.58:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z6_g4_firmware:02.75:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z640_firmware:2.58:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z8_g4_firmware:02.75:*:*:*:*:*:*:*
- cpe:2.3:o:hp:z840_firmware:2.58:*:*:*:*:*:*:*
- cpe:2.3:o:hp:zcentral_4r_firmware:01.18:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- support.hp.com/us-en/document/ish_5670997-5671021-16/hpsbhf03770nvdVendor Advisory
News mentions
0No linked articles in our index yet.