CVE-2022-31646

HIGHCVSS 7.8/10EPSS 0.23%

Last modified

CVE-2022-31646 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.

Description

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.23%

13.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpDragonfly Folio G3 2-In-1 Firmware01.01.03
HpElite Dragonfly Firmware01.21.01
HpElite Dragonfly G3 Firmware01.03.01
HpElite Dragonfly G2 Firmware01.10.00
HpElite Dragonfly Max Firmware01.10.00
HpElite Folio 2-In-1 Firmwarenot_impacted
HpElite X2 1012 G1 Firmware1.57
HpElite X2 1012 G2 Firmware1.43
HpElite X2 1013 G3 Firmware01.21.01
HpElite X2 G4 Firmware01.21.01
HpElite X2 G8 Firmware01.10.00
HpElite X360 1040 G9 2-In-1 Firmware01.03.01
HpElite X360 830 G9 2-In-1 Firmware01.03.01
HpElitebook 1030 G1 Firmware1.57
HpElitebook 1040 G9 Firmware01.03.01
HpElitebook 1040 G3 Firmware1.57
HpElitebook 1040 G4 Firmware1.44
HpElitebook 1050 G1 Firmware01.22.00
HpElitebook 630 G9 Firmware01.04.00
HpElitebook 640 G9 Firmware01.04.00
HpElitebook 645 G9 Firmware01.08.01
HpElitebook 650 G9 Firmware01.04.00
HpElitebook 655 G9 Firmware01.08.01
HpElitebook 735 G5 Firmware01.21.01
HpElitebook 735 G6 Firmware01.21.01
HpElitebook 745 G5 Firmware01.21.01
HpElitebook 745 G6 Firmware01.21.01
HpElitebook 755 G5 Firmware01.21.01
HpElitebook 830 G9 Firmware01.03.01
HpElitebook 830 G5 Firmware01.21.01
HpElitebook 830 G6 Firmware01.21.01
HpElitebook 830 G7 Firmware01.10.00
HpElitebook 830 G8 Firmware01.10.00
HpElitebook 835 G9 Firmware01.02.01
HpElitebook 835 G7 Firmware01.10.00
HpElitebook 835 G8 Firmware01.10.00
HpElitebook 836 G5 Firmware01.21.01
HpElitebook 836 G6 Firmware01.21.01
HpElitebook 840 G9 Firmware01.03.01
HpElitebook 840 Aero G8 Firmware01.10.00
HpElitebook 840 G5 Firmware01.21.01
HpElitebook 840 G6 Firmware01.21.01
HpElitebook 840 G7 Firmware01.10.00
HpElitebook 840 G8 Firmware01.10.00
HpElitebook 840r G4 Firmware01.21.01
HpElitebook 845 G9 Firmware01.02.01
HpElitebook 845 G7 Firmware01.10.00
HpElitebook 845 G8 Firmware01.10.00
HpElitebook 846 G5 Firmware01.21.01
HpElitebook 850 G5 Firmware01.21.01

Showing 50 of 327 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-31646?
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
How severe is CVE-2022-31646?
CVE-2022-31646 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.23% probability of exploitation in the next 30 days.
How do I fix CVE-2022-31646?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-31646?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST