CVE-2022-27540

HIGHCVSS 7.8/10EPSS 0.12%

Last modified

CVE-2022-27540 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.. EPSS estimates a 0.12% chance of exploitation in the next 30 days.

Description

A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS Probability
0.12%

1.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpElitebook 745 G4 Firmware< 1.45
HpElitebook 745 G5 Firmware< 01.26.01
HpElitebook 745 G6 Firmware< 01.26.00
HpElitebook 755 G4 Firmware< 1.45
HpElitebook 755 G5 Firmware< 01.26.01
HpElitebook 820 G3 Firmware< 1.6
HpElitebook 820 G4 Firmware< 1.48
HpElitebook 828 G3 Firmware< 1.6
HpElitebook 828 G4 Firmware< 1.48
HpElitebook 830 13.3 Inch G9 Notebook Pc Firmware< 01.07.00
HpElitebook 830 G5 Firmware< 01.28.00
HpElitebook 830 G6 Firmware< 01.26.00
HpElitebook 830 G7 Firmware< 01.14.00
HpElitebook 830 G8 Firmware< 01.15.02
HpElitebook 835 13 Inch G9 Notebook Pc Firmware< 01.05.01
HpElitebook 735 G6 Firmware< 01.26.00
HpElitebook 735 G5 Firmware< 01.26.01
HpElitebook 725 G4 Firmware< 1.45
HpElitebook 650 15.6 Inch G9 Notebook Pc Firmware< 01.07.00
HpElitebook 640 14 Inch G9 Notebook Pc Firmware< 01.07.00
HpElitebook 630 13 Inch G9 Notebook Pc Firmware< 01.07.00
HpElitebook 1050 G1 Firmware< 01.28.00
HpElitebook 1040 G4 Firmware< 1.5
HpElitebook 1040 G3 Firmware< 1.6
HpElitebook 1040 14 Inch G9 Notebook Pc Firmware< 01.07.00
HpElitebook 1030 G1 Firmware< 1.6
HpElite X360 1040 14 Inch G9 2-In-1 Notebook Pc Firmware< 01.07.00
HpElite X2 G8 Tablet Firmware< 01.11.00
HpElite X2 G4 Firmware01.26.0
HpElite X2 1013 G3 Firmware01.28.00
HpElite X2 1012 G2 Firmware1.48
HpElite X2 1012 G1 Tablet With Travel Keyboard Firmware1.6
HpElite X2 1012 G1 Tablet Firmware1.6
HpElite X2 1012 G1 Firmware< 1.6
HpElite Dragonfly Max Firmware< 01.11.00
HpElite Dragonfly G2 Firmware< 01.11.00
HpElite Dragonfly 13.5 Inch G3 Notebook Pc Firmware< 01.07.00
HpElite Dragonfly Firmware< 01.26.00
HpDragonfly Folio 13.5 Inch G3 2-In-1 Notebook Pc Firmware< 01.07.00
HpElitebook 835 G7 Firmware< 01.14.00
HpProone 440 G6 24 All-In-One Pc Firmware< 02.16.00
HpProone 480 G3 20-Inch Non-Touch All-In One Pc Firmware< 2.48
HpProone 600 G3 21.5-Inch Non-Touch All-In-One Pc Firmware< 2.48
HpProone 600 G4 21.5-Inch Touch All-In-One Business Pc Firmware< 02.29.01
HpProone 600 G5 21.5-In All-In-One Business Pc Firmware< 02.19.00
HpProone 600 G6 22 All-In-One Pc Firmware< 02.16.00
HpZ1 Entry Tower G6 Firmware< 02.16.00
HpZ1 G8 Tower Desktop Pc Firmware< 02.10.00
HpZ1 G9 Tower Desktop Pc Firmware< 02.10.05
HpZhan 66 Pro G3 22 All-In-One Pc Firmware< 02.16.00

Showing 50 of 354 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2022-27540?
A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
How severe is CVE-2022-27540?
CVE-2022-27540 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.12% probability of exploitation in the next 30 days.
How do I fix CVE-2022-27540?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-27540?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST