CVE-2022-31641

HIGHCVSS 7/10EPSS 0.17%

Last modified

CVE-2022-31641 is a high-severity vulnerability rated 7/10 on the CVSS scale. Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

Metrics

CVSS 3.1
7/10

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.17%

6.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpElite Dragonfly Firmware< 01.21.01
HpElite Dragonfly G3 Firmware< 01.03.01
HpElite Dragonfly G3 Firmware< 01.01.03
HpElite X2 1012 G2 Firmware< 1.43
HpElite X2 1013 G3 Firmware< 01.21.01
HpElite X2 G4 Firmware< 01.21.01
HpElite X360 1040 G9 Firmware< 01.03.01
HpElite X360 830 G9 Firmware< 01.03.01
HpElitebook 1040 G9 Firmware< 01.03.01
HpElitebook 1040 G4 Firmware< 1.43
HpElitebook 1050 G1 Firmware< 01.21.02
HpElitebook 630 G9 Firmware< 01.04.00
HpElitebook 640 G9 Firmware< 01.04.00
HpElitebook 645 G9 Firmware< 01.08.01
HpElitebook 650 G9 Firmware< 01.04.00
HpElitebook 655 G9 Firmware< 01.08.01
HpElitebook 725 G4 Firmware< 1.42
HpElitebook 735 G5 Firmware< 01.21.01
HpElitebook 735 G6 Firmware< 01.21.01
HpElitebook 745 G4 Firmware< 1.42
HpElitebook 745 G5 Firmware< 01.21.01
HpElitebook 745 G6 Firmware< 01.21.01
HpElitebook 755 G4 Firmware< 1.42
HpElitebook 755 G5 Firmware< 01.21.01
HpElitebook 820 G4 Firmware< 1.43
HpElitebook 828 G4 Firmware< 1.43
HpElitebook 830 G9 Firmware< 01.03.01
HpElitebook 830 G5 Firmware< 01.21.01
HpElitebook 830 G6 Firmware< 01.21.01
HpElitebook 835 G9 Firmware< 01.02.01
HpElitebook 836 G5 Firmware< 01.21.01
HpElitebook 836 G6 Firmware< 01.21.01
HpElitebook 840 G9 Firmware< 01.03.01
HpElitebook 840 G4 Firmware< 1.43
HpElitebook 840 G5 Firmware< 01.21.01
HpElitebook 840 G5 Healthcare Edition Firmware< 01.21.01
HpElitebook 840 G6 Firmware< 01.21.01
HpElitebook 840 G6 Healthcare Edition Firmware< 01.21.01
HpElitebook 840r G4 Firmware< 01.21.01
HpElitebook 845 G9 Firmware< 01.02.01
HpElitebook 846 G5 Firmware< 01.21.01
HpElitebook 846 G5 Healthcare Edition Firmware< 01.21.01
HpElitebook 846r G4 Firmware< 01.21.01
HpElitebook 848 G4 Firmware< 1.43
HpElitebook 850 G4 Firmware< 1.43
HpElitebook 850 G5 Firmware< 01.21.01
HpElitebook 850 G6 Firmware< 01.21.01
HpElitebook 860 G9 Firmware< 01.03.01
HpElitebook 865 G9 Firmware< 01.02.01
HpElitebook X360 1020 G2 Firmware< 1.43

Showing 50 of 298 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-31641?
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
How severe is CVE-2022-31641?
CVE-2022-31641 has a CVSS score of 7/10 (HIGH severity). The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2022-31641?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-31641?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST