solution Contentsolution Content

SUPPORT COMMUNICATION- SECURITY BULLETIN

Document ID: c05913581

Version: 1

HPSBGN03575 rev. 1 - BIOS Password Extraction Vulnerability on Certain HP Notebooks

Notice: The information in this security bulletin should be acted upon as soon as possible.

Release date : 24-Jan-2018

Last updated : 24-Jan-2018

Potential Security Impact:
The unencrypted password was able to be accessed by CMOS tools.
Source: HP, HP Product Security Response Team (PSRT)
Reported By: Bader Zaidan

VULNERABILITY SUMMARY
A BIOS password extraction vulnerability has been reported on certain consumer notebooks. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.
Reference Number
CVE-2017-2751, PSR-2017-0169
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
Please refer to the RESOLUTION below for the list of potentially impacted HP products.
note:
Consumer notebook products launched late in 2014 are not impacted.
BACKGROUND
For a PGP signed version of this security bulletin please write to: hp-security-alert@hp.com.
CVSS 3.0 Base Metrics
Reference
Base Vector
Base Score
CVE-2017-2751
CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
4.9
Information on CVSS is documented in HP Customer Notice: HPSN­2008­002.
RESOLUTION
HP has released the following softpaqs to mitigate the issue:
Marketing Name
Latest BIOS rev.
Softpaq No.
FTP Link
HP 240 G1 Notebook PC
F.48
TBU
TBU
HP 245 G1 Notebook PC
F.48
TBU
TBU
HP 1000-1300~1000-1399 Notebook PC
F.48
TBU
TBU
Compaq CQ45-900~CQ45-999 Notebook PC
F.48
TBU
TBU
HP 250 G1 Notebook PC
F.47
TBU
TBU
HP 255 G1 Notebook PC
F.47
TBU
TBU
HP ENVY (TouchSmart) 15-j000~j099 Notebook PC
F.22
SP84266
HP ENVY (TouchSmart) 15-j100~j199 Notebook PC
F.71
TBU
TBU
HP Pavilion (TouchSmart) 15-n000~199 Notebook PC
F.72 
TBU
TBU
HP 246 Notebook PC
F.04
TBU
TBU
HP 455 Notebook PC
F.08
TBU
TBU
HP ENVY (TouchSmart) 17-j100~j199 Notebook PC
F.71
TBU
TBU
HP ENVY (TouchSmart) 17-j100 ~ j199 Leap Motion SE Notebook PC
F.71
TBU
TBU
HP Split 13-g200~299 x2 PC
F.25
SP84274
HP ENVY (TouchSmart) 100~15-j199 Notebook PC
F.22
SP84266
HP Pavilion (TouchSmart) 14-n000~199 Notebook PC
F.72 
TBU
TBU
HP ENVY (TouchSmart) 14-k100~14-k199 Sleekbook
F.22
TBU
TBU
HP ENVY TouchSmart 14-k100~14-k199 Ultrabook
F.22
TBU
TBU
HP Spectre x2 13-SMB Pro
F.25
SP84274
HP Spectre 13-h200~299 x2 PC
F.25
SP84274
HP Pavilion 15-n200~299 (TouchSmart) Notebook PC
F.72 
TBU
TBU
HP Pavilion 15-n300~399 (TouchSmart) Notebook PC
F.72 
TBU
TBU
HP ENVY m6-n000~n099 Notebook PC
F.26
SP84537
HP 255 G3 Notebook PC
F.45
SP84257
HP 14-g000~g099 Notebook PC
F.45
SP84257
Compaq 14-h000~h099
F.45
SP84257
HP Pavilion 11-n000~n099 x360 PC
F.2E
SP84131
HP 15-r000~r099 Notebook PC
F.43
SP84418
HP 15-r500~r599 Notebook PC
F.43
SP84418
HP Pavilion 10-f000~f099 Notebook PC
F.0E
TBU
TBU
HP G14-a000~a099 Notebook PC
F.06
SP84377
HP 14-r000~r099 Notebook PC
F.43
SP84418
Compaq 14-s000~s099 Notebook PC
F.43
SP84418
HP 240 G3 Notebook PC
F.43
SP84418
HP 246 G3 Notebook PC
F.43
SP84418
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.

"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
REVISION HISTORY : Version 1: 24 January 2018 Initial release

HP Inc. shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. HP Inc. and the names of HP products referenced herein are trademarks of HP Inc. in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners.