# CVE-2024-5477

## Summary

- **CVE ID:** CVE-2024-5477
- **Severity:** HIGH
- **CVSS Score:** 7.3 (CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-1256
- **Published:** Aug 13, 2025
- **Last Modified:** Mar 13, 2026

## Description

A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escalation of privilege, arbitrary code execution, denial of service, or information disclosure via a physical attack that requires specialized equipment and knowledge.  HP is releasing firmware mitigation for the potential vulnerability.

## Affected Products

- HP Inc. — Certain HP PC Products (See HP Security Bulletin reference for affected versions.)

## References

- [CNA](https://support.hp.com/us-en/document/ish_12878449-12878471-16/hpsbhf04043)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._