CVE-2022-27538
—CVSS 3.1
7.0 high
EPSS
<1%p4
Published
()
Modified
Description
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
- Vendors
- hp
- Products
- dragonfly folio g3 2-in-1 firmware, elite dragonfly firmware, elite dragonfly g3 firmware, elite dragonfly g2 firmware, elite dragonfly max firmware, elite x2 1013 g3 firmware, elite x2 g4 firmware, elite x2 g8 tablet firmware, elite x360 1040 g9 2-in-1 firmware, elitebook 1040 g9 firmware, elitebook 1050 g1 firmware, elitebook 630 g9 firmware
- Weakness
- CWE-367
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.