CVE-2022-31640
Last modified
CVE-2022-31640 is a high-severity vulnerability rated 7/10 on the CVSS scale. Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Elite Dragonfly Firmware | < 01.21.01 |
| Hp | Elite Dragonfly G3 Firmware | < 01.03.01 |
| Hp | Elite Dragonfly G3 Firmware | < 01.01.03 |
| Hp | Elite X2 1012 G2 Firmware | < 1.43 |
| Hp | Elite X2 1013 G3 Firmware | < 01.21.01 |
| Hp | Elite X2 G4 Firmware | < 01.21.01 |
| Hp | Elite X360 1040 G9 Firmware | < 01.03.01 |
| Hp | Elite X360 830 G9 Firmware | < 01.03.01 |
| Hp | Elitebook 1040 G9 Firmware | < 01.03.01 |
| Hp | Elitebook 1040 G4 Firmware | < 1.43 |
| Hp | Elitebook 1050 G1 Firmware | < 01.21.02 |
| Hp | Elitebook 630 G9 Firmware | < 01.04.00 |
| Hp | Elitebook 640 G9 Firmware | < 01.04.00 |
| Hp | Elitebook 645 G9 Firmware | < 01.08.01 |
| Hp | Elitebook 650 G9 Firmware | < 01.04.00 |
| Hp | Elitebook 655 G9 Firmware | < 01.08.01 |
| Hp | Elitebook 725 G4 Firmware | < 1.42 |
| Hp | Elitebook 735 G5 Firmware | < 01.21.01 |
| Hp | Elitebook 735 G6 Firmware | < 01.21.01 |
| Hp | Elitebook 745 G4 Firmware | < 1.42 |
| Hp | Elitebook 745 G5 Firmware | < 01.21.01 |
| Hp | Elitebook 745 G6 Firmware | < 01.21.01 |
| Hp | Elitebook 755 G4 Firmware | < 1.42 |
| Hp | Elitebook 755 G5 Firmware | < 01.21.01 |
| Hp | Elitebook 820 G4 Firmware | < 1.43 |
| Hp | Elitebook 828 G4 Firmware | < 1.43 |
| Hp | Elitebook 830 G9 Firmware | < 01.03.01 |
| Hp | Elitebook 830 G5 Firmware | < 01.21.01 |
| Hp | Elitebook 830 G6 Firmware | < 01.21.01 |
| Hp | Elitebook 835 G9 Firmware | < 01.02.01 |
| Hp | Elitebook 836 G5 Firmware | < 01.21.01 |
| Hp | Elitebook 836 G6 Firmware | < 01.21.01 |
| Hp | Elitebook 840 G9 Firmware | < 01.03.01 |
| Hp | Elitebook 840 G4 Firmware | < 1.43 |
| Hp | Elitebook 840 G5 Firmware | < 01.21.01 |
| Hp | Elitebook 840 G5 Healthcare Edition Firmware | < 01.21.01 |
| Hp | Elitebook 840 G6 Firmware | < 01.21.01 |
| Hp | Elitebook 840 G6 Healthcare Edition Firmware | < 01.21.01 |
| Hp | Elitebook 840r G4 Firmware | < 01.21.01 |
| Hp | Elitebook 845 G9 Firmware | < 01.02.01 |
| Hp | Elitebook 846 G5 Firmware | < 01.21.01 |
| Hp | Elitebook 846 G5 Healthcare Edition Firmware | < 01.21.01 |
| Hp | Elitebook 846r G4 Firmware | < 01.21.01 |
| Hp | Elitebook 848 G4 Firmware | < 1.43 |
| Hp | Elitebook 850 G4 Firmware | < 1.43 |
| Hp | Elitebook 850 G5 Firmware | < 01.21.01 |
| Hp | Elitebook 850 G6 Firmware | < 01.21.01 |
| Hp | Elitebook 860 G9 Firmware | < 01.03.01 |
| Hp | Elitebook 865 G9 Firmware | < 01.02.01 |
| Hp | Elitebook X360 1020 G2 Firmware | < 1.43 |
Showing 50 of 298 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-31640?
How severe is CVE-2022-31640?
How do I fix CVE-2022-31640?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-31631In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.…9.1
- CVE-2022-31635Potential time-of-check to time-of-use (TOCTOU) vulnerabilit…7.8
- CVE-2022-31636Potential time-of-check to time-of-use (TOCTOU) vulnerabilit…7.8
- CVE-2022-31637Potential time-of-check to time-of-use (TOCTOU) vulnerabilit…7.8
- CVE-2022-31638Potential time-of-check to time-of-use (TOCTOU) vulnerabilit…7.8
- CVE-2022-31639Potential time-of-check to time-of-use (TOCTOU) vulnerabilit…7.8
- CVE-2022-31641Potential vulnerabilities have been identified in the system…7
- CVE-2022-31642Potential vulnerabilities have been identified in the system…7
- CVE-2022-31643A potential security vulnerability has been identified in th…5.5
- CVE-2022-31644Potential vulnerabilities have been identified in the system…7.8
- CVE-2022-31645Potential vulnerabilities have been identified in the system…7.8
- CVE-2022-31646Potential vulnerabilities have been identified in the system…7.8
Are you affected by CVE-2022-31640?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
