CVE-2019-6321: HP z4 g4 Core-X Workstation Firmware
High severity, CVSS 7.2. EPSS: 1.4% chance of exploitation in the next 30 days.
HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is disabled by default.
Affected products
- HP z4 g4 Core-X Workstation Firmware: before 1.70 (fixed in 1.70)
- HP z4 g4 Workstation Firmware: before 1.70 (fixed in 1.70)
- HP z6 g4 Workstation Firmware: before 1.71 (fixed in 1.71)
- HP z8 g4 Workstation Firmware: before 1.71 (fixed in 1.71)
Published 2019-05-29. Last modified 2026-06-17.