SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-31645

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

HIGH 7.8EPSS 0.20%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.20% probability · 10th percentile
CISA KEV
Not listed
Weakness
CWE-362
Affected
hp/dragonfly folio g3 2-in-1 firmware · hp/elite dragonfly firmware · hp/elite dragonfly g3 firmware · hp/elite dragonfly g2 firmware · hp/elite dragonfly max firmware · hp/elite folio 2-in-1 firmware · hp/elite x2 1012 g1 firmware · hp/elite x2 1012 g2 firmware · hp/elite x2 1013 g3 firmware · hp/elite x2 g4 firmware · hp/elite x2 g8 firmware · hp/elite x360 1040 g9 2-in-1 firmware · hp/elite x360 830 g9 2-in-1 firmware · hp/elitebook 1030 g1 firmware · hp/elitebook 1040 g9 firmware · hp/elitebook 1040 g3 firmware · hp/elitebook 1040 g4 firmware · hp/elitebook 1050 g1 firmware · hp/elitebook 630 g9 firmware · hp/elitebook 640 g9 firmware · +40 more
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.