CVE-2022-37019
Last modified
CVE-2022-37019 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Elite Slice Firmware | < 00.02.64 |
| Hp | Elite Slice For Meeting Rooms Firmware | < 00.02.64 |
| Hp | Elitebook 1040 G3 Firmware | < 01.62 |
| Hp | Elitebook 820 G3 Firmware | < 01.62 |
| Hp | Elitebook 828 G3 Firmware | < 01.62 |
| Hp | Elitebook 840 G3 Firmware | < 01.62 |
| Hp | Elitebook 848 G3 Firmware | < 01.62 |
| Hp | Elitebook 850 G3 Firmware | < 01.62 |
| Hp | Elitebook Folio G1 Firmware | < 01.62 |
| Hp | Elitedesk 800 35w G2 Desktop Mini Pc Firmware | < 00.02.63 |
| Hp | Elitedesk 800 65w G2 Desktop Mini Pc Firmware | < 00.02.63 |
| Hp | Mp9 G2 Retail System Firmware | < 02.63 |
| Hp | Probook 440 G3 Firmware | < 1.62 |
| Hp | Probook 446 G3 Firmware | < 1.62 |
| Hp | Probook 470 G3 Firmware | < 1.62 |
| Hp | Probook 640 G2 Firmware | < 1.62 |
| Hp | Probook 650 G2 Firmware | < 1.62 |
| Hp | Rp9 G1 Retail System Firmware | < 02.64 |
| Hp | Z2 Mini G3 Workstation Firmware | < 01.91 |
| Hp | Z238 Microtower Workstation Firmware | < 01.91 |
| Hp | Z240 Small Form Factor Workstation Firmware | < 01.91 |
| Hp | Z240 Tower Workstation Firmware | < 01.91 |
| Hp | Zbook 15 G3 Firmware | < 1.62 |
| Hp | Zbook 15u G3 Firmware | < 1.62 |
| Hp | Zbook 17 G3 Firmware | < 1.62 |
| Hp | Zbook Studio G3 Firmware | < 1.62 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-37019?
How severe is CVE-2022-37019?
How do I fix CVE-2022-37019?
Are you affected by CVE-2022-37019?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
