CVE-2022-37020

MEDIUMCVSS 6.8/10EPSS 0.18%

Last modified

CVE-2022-37020 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.

Metrics

CVSS 3.1
6.8/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

EPSS Probability
0.18%

7.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpElite Slice Firmware< 00.02.64
HpElite Slice For Meeting Rooms Firmware< 00.02.64
HpElitebook 1040 G3 Firmware< 01.62
HpElitebook 820 G3 Firmware< 01.62
HpElitebook 828 G3 Firmware< 01.62
HpElitebook 840 G3 Firmware< 01.62
HpElitebook 848 G3 Firmware< 01.62
HpElitebook 850 G3 Firmware< 01.62
HpElitebook Folio G1 Firmware< 01.62
HpElitedesk 800 35w G2 Desktop Mini Pc Firmware< 00.02.63
HpElitedesk 800 65w G2 Desktop Mini Pc Firmware< 00.02.63
HpMp9 G2 Retail System Firmware< 02.63
HpProbook 440 G3 Firmware< 1.62
HpProbook 446 G3 Firmware< 1.62
HpProbook 470 G3 Firmware< 1.62
HpProbook 640 G2 Firmware< 1.62
HpProbook 650 G2 Firmware< 1.62
HpRp9 G1 Retail System Firmware< 02.64
HpZ2 Mini G3 Workstation Firmware< 01.91
HpZ238 Microtower Workstation Firmware< 01.91
HpZ240 Small Form Factor Workstation Firmware< 01.91
HpZ240 Tower Workstation Firmware< 01.91
HpZbook 15 G3 Firmware< 1.62
HpZbook 15u G3 Firmware< 1.62
HpZbook 17 G3 Firmware< 1.62
HpZbook Studio G3 Firmware< 1.62

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2022-37020?
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
How severe is CVE-2022-37020?
CVE-2022-37020 has a CVSS score of 6.8/10 (MEDIUM severity). The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2022-37020?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-37020?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST