SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-48219

Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack.

MEDIUM 6.4EPSS 0.28%

Does this matter?

Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.

Description

Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.

CVSS 3.1
6.4 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
EPSS
0.28% probability · 20th percentile
CISA KEV
Not listed
Weakness
CWE-693
Affected
hp/elite mini 600 g9 firmware · hp/elite mini 800 g9 firmware · hp/elite sff 600 g9 firmware · hp/elite sff 800 g9 firmware · hp/elite tower 600 g9 firmware · hp/elite tower 680 g9 firmware · hp/elite tower 800 g9 firmware · hp/elite tower 880 g9 firmware · hp/pro mini 260 g9 firmware · hp/pro mini 400 g9 firmware · hp/pro sff 400 g9 firmware · hp/pro tower 400 g9 firmware · hp/pro tower 480 g9 firmware · hp/z1 g8 tower firmware · hp/z1 g9 tower firmware · hp/elitedesk 800 g8 desktop mini firmware · hp/elitedesk 800 g8 small form factor firmware · hp/elitedesk 800 g8 tower firmware · hp/elitedesk 880 g8 tower firmware · hp/eliteone 800 g8 24 all-in-one firmware · +7 more
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.