---
cve: "CVE-2024-5477"
severity: "HIGH"
cvss: 7.3
epss: "17%"
vendor: "HP Inc."
kev: false
exploited: false
published: "2025-08-13 18:15:28"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T23:51:43+02:00"
---

# CVE-2024-5477

> 7.3 HIGH

## Beschreibung

A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escalation of privilege, arbitrary code execution, denial of service, or information disclosure via a physical attack that requires specialized equipment and knowledge.  HP is releasing firmware mitigation for the potential vulnerability.

## CVSS-Vektor

```
CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Physisch | good |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://support.hp.com/us-en/document/ish_12878449-12878471-16/hpsbhf04043>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-5477) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
