CVE-2022-31643

MEDIUMCVSS 5.5/10EPSS 0.18%

Last modified

CVE-2022-31643 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability.

Metrics

CVSS 3.1
5.5/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS Probability
0.18%

7.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
HpElite Dragonfly G3 Firmware01.03.01
HpDragonfly Folio G3 Firmware01.03.01
HpElite Dragonfly G2 Firmware01.10.00
HpElite Dragonfly Max Firmware01.10.00
HpElite X2 G8 Firmware01.10.00
HpElite X360 1040 G9 Firmware01.03.01
HpElite X360 830 G9 Firmware01.03.01
HpElitebook 1040 G9 Firmware01.03.01
HpElitebook 630 G9 Firmware01.04.00
HpElitebook 640 G9 Firmware01.04.00
HpElitebook 645 G9 Firmware01.08.01
HpElitebook 650 G9 Firmware01.04.00
HpElitebook 655 G9 Firmware01.08.01
HpElitebook 830 G9 Firmware01.03.01
HpElitebook 830 G8 Firmware01.10.00
HpElitebook 835 G9 Firmware01.02.01
HpElitebook 835 G8 Firmware01.10.00
HpElitebook 840 G9 Firmware01.03.01
HpElitebook 840 Aero G8 Firmware01.10.00
HpElitebook 840 G8 Firmware01.10.00
HpElitebook 845 G9 Firmware01.02.01
HpElitebook 845 G8 Firmware01.10.00
HpElitebook 850 G8 Firmware01.10.00
HpElitebook 855 G8 Firmware01.10.00
HpElitebook 860 G9 Firmware01.03.01
HpElitebook 865 G9 Firmware01.02.01
HpElitebook X360 1030 G8 Firmware01.10.00
HpElitebook X360 1040 G8 Firmware01.10.00
HpElitebook X360 830 G8 Firmware01.10.00
HpPro X360 Fortis G10 Firmware01.03.00
HpPro X360 Fortis G9 Firmware01.03.00
HpProbook 430 G8 Firmware01.10.00
HpProbook 440 G9 Firmware01.04.00
HpProbook 440 G8 Firmware01.10.00
HpProbook 445 G9 Firmware01.08.01
HpProbook 445 G8 Firmware01.10.00
HpProbook 450 G9 Firmware01.04.00
HpProbook 450 G8 Firmware01.10.00
HpProbook 455 G9 Firmware01.08.01
HpProbook 455 G8 Firmware01.10.00
HpProbook 630 G8 Firmware01.10.00
HpProbook 635 Aero G8 Firmware01.10.00
HpProbook 640 G8 Firmware01.10.00
HpProbook 650 G8 Firmware01.10.00
HpProbook Fortis G10 Firmware01.03.00
HpProbook Fortis G9 Firmware01.03.00
HpProbook X360 11 G7 Ee Firmware01.10.00
HpProbook X360 435 G8 Firmware01.10.00
HpZbook Firefly G8 Firmware01.10.00
HpZbook Firefly G9 Firmware01.03.01

Showing 50 of 91 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-31643?
A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability.
How severe is CVE-2022-31643?
CVE-2022-31643 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2022-31643?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-31643?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST