CVE-2022-31636

HIGHCVSS 7.8/10EPSS 0.14%

Last modified

CVE-2022-31636 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.

Description

Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS Probability
0.14%

3.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpZcentral 4r Workstation Firmware<= 1.24
HpZ1 All-In-One G3 Workstation Firmware<= 1.33
HpElitebook 725 G4 Firmware<= 1.42
HpElitebook 745 G4 Firmware<= 1.42
HpElitebook 755 G4 Firmware<= 1.42
HpProbook 645 G3 Firmware<= 1.42
HpProbook 655 G3 Firmware<= 1.42
HpMt43 Mobile Thin Client Firmware<= 1.42
HpElite X2 1012 G2 Firmware<= 1.43
HpElitebook 1040 G4 Firmware<= 1.43
HpElitebook 820 G4 Firmware<= 1.43
HpElitebook 828 G4 Firmware<= 1.43
HpElitebook 840 G4 Firmware<= 1.43
HpElitebook 848 G4 Firmware<= 1.43
HpElitebook 850 G4 Firmware<= 1.43
HpElitebook X360 1020 G2 Firmware<= 1.43
HpElitebook X360 1030 G2 Firmware<= 1.43
HpPro X2 612 G2 Firmware<= 1.43
HpProbook 455 G4 Firmware<= 1.43
HpProbook 640 G3 Firmware<= 1.43
HpProbook 650 G3 Firmware<= 1.43
HpZbook 14u G4 Firmware<= 1.43
HpZbook 15 G4 Firmware<= 1.43
HpZbook 15u G4 Firmware<= 1.43
HpZbook 17 G4 Firmware<= 1.43
HpZbook Studio G4 Firmware<= 1.43
HpZbook X2 G4 Firmware<= 1.43
HpProbook X360 11 G2 Ee Firmware<= 1.45
HpElitebook 725 G3 Firmware<= 1.55
HpElitebook 745 G3 Firmware<= 1.55
HpElitebook 755 G3 Firmware<= 1.55
HpProbook 455 G3 Firmware<= 1.55
HpProbook 645 G2 Firmware<= 1.55
HpProbook 655 G2 Firmware<= 1.55
HpElite X2 1012 G1 Firmware<= 1.57
HpElite X2 1012 G1 Tablet Firmware<= 1.57
HpElite X2 1012 G1 Tablet With Travel Keyboard Firmware<= 1.57
HpElitebook 1030 G1 Firmware<= 1.57
HpElitebook 1040 G3 Firmware<= 1.57
HpElitebook 820 G3 Firmware<= 1.57
HpElitebook 828 G3 Firmware<= 1.57
HpElitebook 840 G3 Firmware<= 1.57
HpElitebook 848 G3 Firmware<= 1.57
HpElitebook 850 G3 Firmware<= 1.57
HpElitebook Folio G1 Firmware<= 1.57
HpProbook 11 Ee G2 Firmware<= 1.57
HpProbook 430 G3 Firmware<= 1.57
HpProbook 440 G3 Firmware<= 1.57
HpProbook 446 G3 Firmware<= 1.57
HpProbook 450 G3 Firmware<= 1.57

Showing 50 of 403 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-31636?
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
How severe is CVE-2022-31636?
CVE-2022-31636 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.14% probability of exploitation in the next 30 days.
How do I fix CVE-2022-31636?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-31636?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST