ZeroHour

CVE-2022-43779

CVSS 3.1
7.0 high
EPSS
<1%p3
Published
()
Modified
Description

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability.

Vendors
hp
Products
348 g4 firmware, 260 g2 desktop mini firmware, 218 pro g5 mt firmware, 260 g3 desktop mini firmware, 260 g4 desktop mini firmware, 280 g3 microtower pc firmware, 280 g3 pci microtower pc firmware, 288 pro g3 microtower pc firmware, 290 g1 microtower firmware, desktop pro 300 g3 firmware, desktop pro a 300 g3 firmware, desktop pro a g2 firmware
Weakness
CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.