CVE-2022-48219
Last modified
CVE-2022-48219 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Elite Mini 600 G9 Firmware | < 02.12.02 |
| Hp | Elite Mini 800 G9 Firmware | < 02.12.02 |
| Hp | Elite Sff 600 G9 Firmware | < 02.12.02 |
| Hp | Elite Sff 800 G9 Firmware | < 02.12.02 |
| Hp | Elite Tower 600 G9 Firmware | < 02.12.02 |
| Hp | Elite Tower 680 G9 Firmware | < 02.12.02 |
| Hp | Elite Tower 800 G9 Firmware | < 02.12.02 |
| Hp | Elite Tower 880 G9 Firmware | < 02.12.02 |
| Hp | Pro Mini 260 G9 Firmware | < 02.14.00 |
| Hp | Pro Mini 400 G9 Firmware | < 02.12.02 |
| Hp | Pro Sff 400 G9 Firmware | < 02.12.02 |
| Hp | Pro Tower 400 G9 Firmware | < 02.12.02 |
| Hp | Pro Tower 480 G9 Firmware | < 02.12.02 |
| Hp | Z1 G8 Tower Firmware | < 02.14.00 |
| Hp | Z1 G9 Tower Firmware | < 02.12.02 |
| Hp | Elitedesk 800 G8 Desktop Mini Firmware | < 02.14.00 |
| Hp | Elitedesk 800 G8 Small Form Factor Firmware | < 02.14.00 |
| Hp | Elitedesk 800 G8 Tower Firmware | < 02.14.00 |
| Hp | Elitedesk 880 G8 Tower Firmware | < 02.14.00 |
| Hp | Eliteone 800 G8 24 All-In-One Firmware | < 02.14.00 |
| Hp | Eliteone 800 G8 27 All-In-One Firmware | < 02.14.00 |
| Hp | Mini Conferencing Pc Firmware | < 02.12.02 |
| Hp | Z2 Mini G9 Firmware | < 02.02.02 |
| Hp | Z2 Small Form Factor G8 Firmware | < 01.06.05 |
| Hp | Z2 Small Form Factor G9 Firmware | < 02.02.02 |
| Hp | Z2 Tower G8 Firmware | < 01.06.05 |
| Hp | Z2 Tower G9 Firmware | < 02.02.02 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-48219?
How severe is CVE-2022-48219?
How do I fix CVE-2022-48219?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-48198The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 …9.8
- CVE-2022-48199SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to e…8.8
- CVE-2022-4820A vulnerability classified as problematic has been found in …6.1
- CVE-2022-4821A vulnerability classified as problematic was found in FlatP…6.1
- CVE-2022-48216Uniswap Universal Router before 1.1.0 mishandles reentrancy.…7.5
- CVE-2022-48217The tf_remapper_node component 1.1.1 for Robot Operating Sys…8.1
- CVE-2022-4822A vulnerability, which was classified as problematic, has be…6.1
- CVE-2022-48220Potential vulnerabilities have been identified in certain HP…6.4
- CVE-2022-48221An issue was discovered in Acuant AcuFill SDK before 10.22.0…7.5
- CVE-2022-48222An issue was discovered in Acuant AcuFill SDK before 10.22.0…7.8
- CVE-2022-48223An issue was discovered in Acuant AcuFill SDK before 10.22.0…6.7
- CVE-2022-48224An issue was discovered in Acuant AcuFill SDK before 10.22.0…7.3
Are you affected by CVE-2022-48219?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
