CVE-2022-43778
Last modified
CVE-2022-43778 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Zcentral 4r Workstation Firmware | <= 1.24 |
| Hp | Z1 All-In-One G3 Workstation Firmware | <= 1.33 |
| Hp | Elitebook 725 G4 Firmware | <= 1.42 |
| Hp | Elitebook 745 G4 Firmware | <= 1.42 |
| Hp | Elitebook 755 G4 Firmware | <= 1.42 |
| Hp | Probook 645 G3 Firmware | <= 1.42 |
| Hp | Probook 655 G3 Firmware | <= 1.42 |
| Hp | Mt43 Mobile Thin Client Firmware | <= 1.42 |
| Hp | Elite X2 1012 G2 Firmware | <= 1.43 |
| Hp | Elitebook 1040 G4 Firmware | <= 1.43 |
| Hp | Elitebook 820 G4 Firmware | <= 1.43 |
| Hp | Elitebook 828 G4 Firmware | <= 1.43 |
| Hp | Elitebook 840 G4 Firmware | <= 1.43 |
| Hp | Elitebook 848 G4 Firmware | <= 1.43 |
| Hp | Elitebook 850 G4 Firmware | <= 1.43 |
| Hp | Elitebook X360 1020 G2 Firmware | <= 1.43 |
| Hp | Elitebook X360 1030 G2 Firmware | <= 1.43 |
| Hp | Pro X2 612 G2 Firmware | <= 1.43 |
| Hp | Probook 455 G4 Firmware | <= 1.43 |
| Hp | Probook 640 G3 Firmware | <= 1.43 |
| Hp | Probook 650 G3 Firmware | <= 1.43 |
| Hp | Zbook 14u G4 Firmware | <= 1.43 |
| Hp | Zbook 15 G4 Firmware | <= 1.43 |
| Hp | Zbook 15u G4 Firmware | <= 1.43 |
| Hp | Zbook 17 G4 Firmware | <= 1.43 |
| Hp | Zbook Studio G4 Firmware | <= 1.43 |
| Hp | Zbook X2 G4 Firmware | <= 1.43 |
| Hp | Probook X360 11 G2 Ee Firmware | <= 1.45 |
| Hp | Elitebook 725 G3 Firmware | <= 1.55 |
| Hp | Elitebook 745 G3 Firmware | <= 1.55 |
| Hp | Elitebook 755 G3 Firmware | <= 1.55 |
| Hp | Probook 455 G3 Firmware | <= 1.55 |
| Hp | Probook 645 G2 Firmware | <= 1.55 |
| Hp | Probook 655 G2 Firmware | <= 1.55 |
| Hp | Elite X2 1012 G1 Firmware | <= 1.57 |
| Hp | Elite X2 1012 G1 Tablet Firmware | <= 1.57 |
| Hp | Elite X2 1012 G1 Tablet With Travel Keyboard Firmware | <= 1.57 |
| Hp | Elitebook 1030 G1 Firmware | <= 1.57 |
| Hp | Elitebook 1040 G3 Firmware | <= 1.57 |
| Hp | Elitebook 820 G3 Firmware | <= 1.57 |
| Hp | Elitebook 828 G3 Firmware | <= 1.57 |
| Hp | Elitebook 840 G3 Firmware | <= 1.57 |
| Hp | Elitebook 848 G3 Firmware | <= 1.57 |
| Hp | Elitebook 850 G3 Firmware | <= 1.57 |
| Hp | Elitebook Folio G1 Firmware | <= 1.57 |
| Hp | Probook 11 Ee G2 Firmware | <= 1.57 |
| Hp | Probook 430 G3 Firmware | <= 1.57 |
| Hp | Probook 440 G3 Firmware | <= 1.57 |
| Hp | Probook 446 G3 Firmware | <= 1.57 |
| Hp | Probook 450 G3 Firmware | <= 1.57 |
Showing 50 of 387 affected configurations. See NVD for the full list.
References
- https://support.hp.com/us-en/document/ish_7709808-7709835-16/hpsbhf03835Exploit, Vendor Advisory
- https://support.hp.com/us-en/document/ish_7709808-7709835-16/hpsbhf03835Exploit, Vendor Advisory
- https://support.hp.com/us-en/document/ish_7709808-7709835-16/hpsbhf03835Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-43778?
How severe is CVE-2022-43778?
How do I fix CVE-2022-43778?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-43772 Hitachi Vantara Pentaho Business Analytics Server versions …6.5
- CVE-2022-43773 Hitachi Vantara Pentaho Business Analytics Server prior to …8.8
- CVE-2022-43774The HandlerPageP_KID class in Delta Electronics DIAEnergy v1…9.8
- CVE-2022-43775The HICT_Loop class in Delta Electronics DIAEnergy v1.9 cont…9.8
- CVE-2022-43776The url parameter of the /api/geojson endpoint in Metabase v…6.5
- CVE-2022-43777Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilit…7.8
- CVE-2022-43779A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerabil…7
- CVE-2022-4378A stack overflow flaw was found in the Linux kernel's SYSCTL…7.8
- CVE-2022-43780Certain HP ENVY, OfficeJet, and DeskJet printers may be vuln…7.5
- CVE-2022-43781There is a command injection vulnerability using environment…9.8
- CVE-2022-43782Affected versions of Atlassian Crowd allow an attacker to au…9.8
- CVE-2022-43783Rejected reason: To maintain compliance with CNA rules, we h…
Are you affected by CVE-2022-43778?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
