CVE-2022-37019
Last modified
CVE-2022-37019 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Elite Slice Firmware | < 00.02.64 |
| Hp | Elite Slice For Meeting Rooms Firmware | < 00.02.64 |
| Hp | Elitebook 1040 G3 Firmware | < 01.62 |
| Hp | Elitebook 820 G3 Firmware | < 01.62 |
| Hp | Elitebook 828 G3 Firmware | < 01.62 |
| Hp | Elitebook 840 G3 Firmware | < 01.62 |
| Hp | Elitebook 848 G3 Firmware | < 01.62 |
| Hp | Elitebook 850 G3 Firmware | < 01.62 |
| Hp | Elitebook Folio G1 Firmware | < 01.62 |
| Hp | Elitedesk 800 35w G2 Desktop Mini Pc Firmware | < 00.02.63 |
| Hp | Elitedesk 800 65w G2 Desktop Mini Pc Firmware | < 00.02.63 |
| Hp | Mp9 G2 Retail System Firmware | < 02.63 |
| Hp | Probook 440 G3 Firmware | < 1.62 |
| Hp | Probook 446 G3 Firmware | < 1.62 |
| Hp | Probook 470 G3 Firmware | < 1.62 |
| Hp | Probook 640 G2 Firmware | < 1.62 |
| Hp | Probook 650 G2 Firmware | < 1.62 |
| Hp | Rp9 G1 Retail System Firmware | < 02.64 |
| Hp | Z2 Mini G3 Workstation Firmware | < 01.91 |
| Hp | Z238 Microtower Workstation Firmware | < 01.91 |
| Hp | Z240 Small Form Factor Workstation Firmware | < 01.91 |
| Hp | Z240 Tower Workstation Firmware | < 01.91 |
| Hp | Zbook 15 G3 Firmware | < 1.62 |
| Hp | Zbook 15u G3 Firmware | < 1.62 |
| Hp | Zbook 17 G3 Firmware | < 1.62 |
| Hp | Zbook Studio G3 Firmware | < 1.62 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-37019?
How severe is CVE-2022-37019?
How do I fix CVE-2022-37019?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-37012This vulnerability allows remote attackers to create a denia…7.5
- CVE-2022-37013This vulnerability allows remote attackers to create a denia…7.5
- CVE-2022-37015Symantec Endpoint Detection and Response (SEDR) Appliance, p…9.8
- CVE-2022-37016Symantec Endpoint Protection (Windows) agent may be suscepti…9.8
- CVE-2022-37017Symantec Endpoint Protection (Windows) agent, prior to 14.3 …7.5
- CVE-2022-37018A potential vulnerability has been identified in the system …8.4
- CVE-2022-3702 A denial of service vulnerability was reported in Lenovo Va…7.1
- CVE-2022-37020Potential vulnerabilities have been identified in the system…6.8
- CVE-2022-37021Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vu…9.8
- CVE-2022-37022Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable…8.8
- CVE-2022-37023Apache Geode versions prior to 1.15.0 are vulnerable to a de…6.5
- CVE-2022-37024Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, …8.8
Are you affected by CVE-2022-37019?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
