CVE-2023-6138
Estado: AnalizadaAlta (7.9)—
A potential security vulnerability has been identified in the system BIOS for certain HP Workstation PCs, which might allow escalation of privilege, arbitrary code execution, or denial of service. HP is releasing mitigation for the potential vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
- Puntuación base: 7.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-6138",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-6138",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-08-28T13:57:07.063493Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.9,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 5.8,
"exploitabilityScore": 1.5
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.9,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 5.8,
"exploitabilityScore": 1.5
}
]
},
"affected": [
{
"source": "hp-security-alert@hp.com",
"affectedData": [
{
"vendor": "HP Inc.",
"product": "Certain HP Workstation PCs",
"versions": [
{
"status": "affected",
"version": "See HP Security Bulletin reference for affected versions."
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-02-14T23:15:08.093",
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_10167884-10167908-16/hpsbhf03915",
"tags": [
"Vendor Advisory"
],
"source": "hp-security-alert@hp.com"
},
{
"url": "https://support.hp.com/us-en/document/ish_10167884-10167908-16/hpsbhf03915",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A potential security vulnerability has been identified in the system BIOS for certain HP Workstation PCs, which might allow escalation of privilege, arbitrary code execution, or denial of service. HP is releasing mitigation for the potential vulnerability."
},
{
"lang": "es",
"value": "Se ha identificado una posible vulnerabilidad de seguridad en el BIOS del sistema para ciertas estaciones de trabajo HP, que podría permitir una escalada de privilegios, la ejecución de código arbitrario o la denegación de servicio. HP está lanzando medidas de mitigación para la posible vulnerabilidad."
}
],
"lastModified": "2026-06-17T06:50:07.747",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hp:z440_workstation_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1AF1843D-5AFD-4517-83DE-E0777E8CC6C5",
"versionEndExcluding": "2.62"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hp:z440_workstation:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C19FBDF8-4762-4341-886E-1145CF5D9DEE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hp:z640_workstation_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3BC9748B-151F-46C1-B13C-74D7DA938B0F",
"versionEndExcluding": "2.62"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hp:z640_workstation:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C495E312-0337-42EC-9A0D-83CF3689A840"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hp:z840_workstation_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B64DA921-B013-4C84-9C32-AE19EE33291D",
"versionEndExcluding": "2.62"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hp:z840_workstation:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C2B5C04D-4BFF-4BF3-AB55-B443990EF136"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "hp-security-alert@hp.com"
}