CVE-2022-48219

MEDIUMCVSS 6.4/10EPSS 0.28%

Last modified

CVE-2022-48219 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.

Description

Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.

Metrics

CVSS 3.1
6.4/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

EPSS Probability
0.28%

19.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpElite Mini 600 G9 Firmware< 02.12.02
HpElite Mini 800 G9 Firmware< 02.12.02
HpElite Sff 600 G9 Firmware< 02.12.02
HpElite Sff 800 G9 Firmware< 02.12.02
HpElite Tower 600 G9 Firmware< 02.12.02
HpElite Tower 680 G9 Firmware< 02.12.02
HpElite Tower 800 G9 Firmware< 02.12.02
HpElite Tower 880 G9 Firmware< 02.12.02
HpPro Mini 260 G9 Firmware< 02.14.00
HpPro Mini 400 G9 Firmware< 02.12.02
HpPro Sff 400 G9 Firmware< 02.12.02
HpPro Tower 400 G9 Firmware< 02.12.02
HpPro Tower 480 G9 Firmware< 02.12.02
HpZ1 G8 Tower Firmware< 02.14.00
HpZ1 G9 Tower Firmware< 02.12.02
HpElitedesk 800 G8 Desktop Mini Firmware< 02.14.00
HpElitedesk 800 G8 Small Form Factor Firmware< 02.14.00
HpElitedesk 800 G8 Tower Firmware< 02.14.00
HpElitedesk 880 G8 Tower Firmware< 02.14.00
HpEliteone 800 G8 24 All-In-One Firmware< 02.14.00
HpEliteone 800 G8 27 All-In-One Firmware< 02.14.00
HpMini Conferencing Pc Firmware< 02.12.02
HpZ2 Mini G9 Firmware< 02.02.02
HpZ2 Small Form Factor G8 Firmware< 01.06.05
HpZ2 Small Form Factor G9 Firmware< 02.02.02
HpZ2 Tower G8 Firmware< 01.06.05
HpZ2 Tower G9 Firmware< 02.02.02

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2022-48219?
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.
How severe is CVE-2022-48219?
CVE-2022-48219 has a CVSS score of 6.4/10 (MEDIUM severity). The EPSS model estimates a 0.28% probability of exploitation in the next 30 days.
How do I fix CVE-2022-48219?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-48219?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST