« Volver al listado

CVE-2023-5409

Estado: ModificadaMedia (6.8)—

HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack, allowing an untrusted source to tamper with the system firmware using a publicly disclosed private key. HP is providing recommended guidance for customers to reduce exposure to the potential vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-5409",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "hp-security-alert@hp.com",
      "affectedData": [
        {
          "vendor": "HP Inc.",
          "product": "HP t430 and t638 Thin Clients",
          "versions": [
            {
              "status": "affected",
              "version": "See HP Security Bulletin for affected products."
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-10-13T17:15:09.713",
  "references": [
    {
      "url": "https://support.hp.com/us-en/document/ish_9441200-9441233-16",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "https://support.hp.com/us-en/document/ish_9441200-9441233-16",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack, allowing an untrusted source to tamper with the system firmware using a publicly disclosed private key. HP is providing recommended guidance for customers to reduce exposure to the potential vulnerability."
    },
    {
      "lang": "es",
      "value": "HP es consciente de una posible vulnerabilidad de seguridad en las PC Thin Client HP t430 y t638. Estos modelos pueden ser susceptibles a un ataque físico, lo que permite que una fuente no confiable altere el firmware del sistema utilizando una clave privada divulgada públicamente. HP proporciona orientación recomendada para que los clientes reduzcan la exposición a la vulnerabilidad potencial."
    }
  ],
  "lastModified": "2026-06-17T06:48:32.173",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hp:t430_thin_client_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D57D386-8265-4EF7-B88A-A57F68233E1E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hp:t430_thin_client:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "33625E33-810C-441F-BFEC-A62CF2DC57BF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hp:t638_thin_client_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86E50369-0AA4-41E1-A0BA-18C5C3F7FE91"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hp:t638_thin_client:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "088B2E46-7977-4F8B-B440-471E188A84C3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "hp-security-alert@hp.com"
}