CVE-2023-5409
Estado: ModificadaMedia (6.8)—
HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack, allowing an untrusted source to tamper with the system firmware using a publicly disclosed private key. HP is providing recommended guidance for customers to reduce exposure to the potential vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.29%
- Percentil entre todas las CVEs puntuadas: 20
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-5409",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "hp-security-alert@hp.com",
"affectedData": [
{
"vendor": "HP Inc.",
"product": "HP t430 and t638 Thin Clients",
"versions": [
{
"status": "affected",
"version": "See HP Security Bulletin for affected products."
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2023-10-13T17:15:09.713",
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_9441200-9441233-16",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "hp-security-alert@hp.com"
},
{
"url": "https://support.hp.com/us-en/document/ish_9441200-9441233-16",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack, allowing an untrusted source to tamper with the system firmware using a publicly disclosed private key. HP is providing recommended guidance for customers to reduce exposure to the potential vulnerability."
},
{
"lang": "es",
"value": "HP es consciente de una posible vulnerabilidad de seguridad en las PC Thin Client HP t430 y t638. Estos modelos pueden ser susceptibles a un ataque físico, lo que permite que una fuente no confiable altere el firmware del sistema utilizando una clave privada divulgada públicamente. HP proporciona orientación recomendada para que los clientes reduzcan la exposición a la vulnerabilidad potencial."
}
],
"lastModified": "2026-06-17T06:48:32.173",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hp:t430_thin_client_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6D57D386-8265-4EF7-B88A-A57F68233E1E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hp:t430_thin_client:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "33625E33-810C-441F-BFEC-A62CF2DC57BF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hp:t638_thin_client_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "86E50369-0AA4-41E1-A0BA-18C5C3F7FE91"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hp:t638_thin_client:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "088B2E46-7977-4F8B-B440-471E188A84C3"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "hp-security-alert@hp.com"
}