SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-27540

A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure.

HIGH 7.8EPSS 0.12%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS
0.12% probability · 2th percentile
CISA KEV
Not listed
Weakness
CWE-367
Affected
hp/elitebook 745 g4 firmware · hp/elitebook 745 g5 firmware · hp/elitebook 745 g6 firmware · hp/elitebook 755 g4 firmware · hp/elitebook 755 g5 firmware · hp/elitebook 820 g3 firmware · hp/elitebook 820 g4 firmware · hp/elitebook 828 g3 firmware · hp/elitebook 828 g4 firmware · hp/elitebook 830 13.3 inch g9 notebook pc firmware · hp/elitebook 830 g5 firmware · hp/elitebook 830 g6 firmware · hp/elitebook 830 g7 firmware · hp/elitebook 830 g8 firmware · hp/elitebook 835 13 inch g9 notebook pc firmware · hp/elitebook 735 g6 firmware · hp/elitebook 735 g5 firmware · hp/elitebook 725 g4 firmware · hp/elitebook 650 15.6 inch g9 notebook pc firmware · hp/elitebook 640 14 inch g9 notebook pc firmware · +40 more
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.