VulnerabilityModified
CVE-2022-37018
A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution.
HIGH 8.4EPSS 0.24%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability.
- CVSS 3.1
- 8.4 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.24% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- hp/z1 g3 firmware · hp/z2 mini g3 firmware · hp/z238 microtower firmware · hp/z240 sff firmware · hp/z240 tower firmware · hp/engage one aio system firmware · hp/mp9 g2 retail system firmware · hp/rp9 g1 retail system firmware · hp/elite slice firmware · hp/elitedesk 800 35w g2 desktop mini pc firmware · hp/elitedesk 800 35w g3 desktop mini pc firmware · hp/elitedesk 800 65w g2 desktop mini pc firmware · hp/elitedesk 800 65w g3 desktop mini pc firmware · hp/elitedesk 800 g2 sff firmware · hp/eliteone 800 g2 aio firmware · hp/eliteone 800 g3 firmware · hp/prodesk 400 g3 dm firmware · hp/prodesk 400 g4 microtower firmware · hp/prodesk 400 g4 sff firmware · hp/prodesk 480 g4 microtower pc firmware · +40 more
- Source
- hp-security-alert@hp.com
References
- https://support.hp.com/us-en/document/ish_7191946-7191970-16/hpsbhf03820Patch, Vendor Advisory
- https://support.hp.com/us-en/document/ish_7191946-7191970-16/hpsbhf03820Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.