CVE-2022-27540
—CVSS 3.1
7.8 high
EPSS
<1%p2
Published
()
Modified
Description
A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
- Vendors
- hp
- Products
- elitebook 745 g4 firmware, elitebook 745 g5 firmware, elitebook 745 g6 firmware, elitebook 755 g4 firmware, elitebook 755 g5 firmware, elitebook 820 g3 firmware, elitebook 820 g4 firmware, elitebook 828 g3 firmware, elitebook 828 g4 firmware, elitebook 830 13.3 inch g9 notebook pc firmware, elitebook 830 g5 firmware, elitebook 830 g6 firmware
- Weakness
- CWE-367
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.