About
Careers
Support
Partners
Community
Contact
Product
Overview
IT Discovery
IT Inventory
IT Analytics
Features
Integrations
Use Cases
IT Asset Management
Cybersecurity
Active Directory Audit
Installing Software & Patches
Automated IT Inventory
Pricing
Resources
Support Knowledge Base
Videos
Testimonials
Vulnerability Updates
Patch Tuesday
Blog
Free Download
Lansweeper
»
Vulnerability Reports
»
HP BIOS Vulnerability
Active Topics
Search
Join Now
Login
Notification
Error
OK
HP BIOS Vulnerability
Posted:
Thursday, May 12, 2022 1:10:58 PM(UTC)
Esben.D
Member
Administration
Original Poster
Posts: 2,187
1
Like
Two new vulnerabilities have been fixed for 200+ HP models, you can find the audit in the
HP BIOS vulnerability blog post.
#1
snigah
Member
Posts: 14
posted:
5/18/2022 9:28:00 PM(UTC)
Hi,
Question. How can we make it work correct. we have lots of false positives, because it doesn't compare current Bios version against the fixed one.
Just one example:
the R72 is current and 01.20.00 where 01.12.00 is the fixed version.
R72 Ver. 01.20.00 R72 Ver. 01.20.00 3 1 2022-03-18 01.12.00
User Profile
View All Posts by User
View helpful posts
#2
JakeST
Member
Posts: 2
posted:
5/19/2022 3:43:06 PM(UTC)
Originally Posted by: snigah
Hi,
Question. How can we make it work correct. we have lots of false positives, because it doesn't compare current Bios version against the fixed one.
Just one example:
the R72 is current and 01.20.00 where 01.12.00 is the fixed version.
R72 Ver. 01.20.00 R72 Ver. 01.20.00 3 1 2022-03-18 01.12.00
Same here. It would be nice to have this compare and only show vulnerable machines, or color code ones that are updated vs ones that aren't.
User Profile
View All Posts by User
View helpful posts
#3
Esben.D
Member
Administration
Original Poster
Posts: 2,187
posted:
5/20/2022 8:44:52 AM(UTC)
I totally agree. The problem is that BIOS versions come in all sizes and shapes and unless I investigate all affected models it's not possible for me to create a condition that will reliably work.
For example, many BIOS versions will have letters in them which would break any comparison of versions when you're trying to check if 20 > 2B.
User Profile
View All Posts by User
View helpful posts
Active Discussions
Version 10.2.0.0
by
ThomasK
Last post:
Today
at 6:11:28 AM(UTC)
Certificates
by
Orion Poplawski
Last post:
7/1/2022 10:11:12 PM(UTC)
Lansweeper sends "Lansweeper Connection Test" emails every minute.
by
FrankSc
Last post:
7/1/2022 2:03:59 PM(UTC)
Dell warranty lookup not working
by
LANGuy
Last post:
7/1/2022 1:30:06 PM(UTC)
RedHat 8.5 & SELinux
by
QuelleAcht
Last post:
7/1/2022 1:16:19 PM(UTC)
Suddenly seeing Access Denied scanning errors?
by
Erik.T
Last post:
7/1/2022 9:38:17 AM(UTC)
Single Line report with H/D
by
Ioannis
Last post:
7/1/2022 7:53:23 AM(UTC)
Lansweeper Dark Theme
by
mrobbins
Last post:
6/30/2022 5:38:01 PM(UTC)