SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-37019

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution.

MEDIUM 6.8EPSS 0.17%

Does this matter?

Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.

Description

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
EPSS
0.17% probability · 6th percentile
CISA KEV
Not listed
Weakness
CWE-269
Affected
hp/elite slice firmware · hp/elite slice for meeting rooms firmware · hp/elitebook 1040 g3 firmware · hp/elitebook 820 g3 firmware · hp/elitebook 828 g3 firmware · hp/elitebook 840 g3 firmware · hp/elitebook 848 g3 firmware · hp/elitebook 850 g3 firmware · hp/elitebook folio g1 firmware · hp/elitedesk 800 35w g2 desktop mini pc firmware · hp/elitedesk 800 65w g2 desktop mini pc firmware · hp/mp9 g2 retail system firmware · hp/probook 440 g3 firmware · hp/probook 446 g3 firmware · hp/probook 470 g3 firmware · hp/probook 640 g2 firmware · hp/probook 650 g2 firmware · hp/rp9 g1 retail system firmware · hp/z2 mini g3 workstation firmware · hp/z238 microtower workstation firmware · +6 more
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.