8.4

CVE-2022-37018

A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability.

Data is provided by the National Vulnerability Database (NVD)
HpZ1 G3 Firmware Version < 01.33
   HpZ1 G3 Version-
HpZ2 Mini G3 Firmware Version < 01.85
   HpZ2 Mini G3 Version-
HpZ238 Microtower Firmware Version < 01.85
   HpZ238 Microtower Version-
HpZ240 Sff Firmware Version < 01.85
   HpZ240 Sff Version-
HpZ240 Tower Firmware Version < 01.85
   HpZ240 Tower Version-
HpEngage One Aio System Firmware Version < 02.44
   HpEngage One Aio System Version-
HpMp9 G2 Retail System Firmware Version < 02.59
   HpMp9 G2 Retail System Version-
HpRp9 G1 Retail System Firmware Version < 02.59
   HpRp9 G1 Retail System Version-
HpElite Slice Firmware Version < 02.59
   HpElite Slice Version-
HpElitedesk 800 G2 Sff Firmware Version < 02.59
   HpElitedesk 800 G2 Sff Version-
HpEliteone 800 G2 Aio Firmware Version < 02.59
   HpEliteone 800 G2 Aio Version-
HpEliteone 800 G3 Firmware Version < 02.44
   HpEliteone 800 G3 Version-
HpProdesk 400 G3 Dm Firmware Version < 02.44
   HpProdesk 400 G3 Dm Version-
HpProdesk 400 G4 Microtower Firmware Version < 02.44
   HpProdesk 400 G4 Microtower Version-
HpProdesk 400 G4 Sff Firmware Version < 02.44
   HpProdesk 400 G4 Sff Version-
HpProdesk 600 G2 Dm Firmware Version < 02.59
   HpProdesk 600 G2 Dm Version-
HpProdesk 600 G2 Sff Firmware Version < 02.59
   HpProdesk 600 G2 Sff Version-
HpProdesk 600 G3 Sff Firmware Version < 02.44
   HpProdesk 600 G3 Sff Version-
HpProone 400 G2 Aio Firmware Version < 02.59
   HpProone 400 G2 Aio Version-
HpProone 400 G3 Aio Firmware Version < 02.44
   HpProone 400 G3 Aio Version-
HpProone 480 G3 Firmware Version < 02.44
   HpProone 480 G3 Version-
HpProone 600 G2 Aio Firmware Version < 02.59
   HpProone 600 G2 Aio Version-
HpProone 600 G3 Firmware Version < 02.44
   HpProone 600 G3 Version-
HpElite X2 1012 G1 Firmware Version < 01.58
   HpElite X2 1012 G1 Version-
HpElite X2 1012 G2 Firmware Version < 01.44
   HpElite X2 1012 G2 Version-
HpElitebook 1030 G1 Firmware Version < 01.58
   HpElitebook 1030 G1 Version-
HpElitebook 1040 G3 Firmware Version < 01.58
   HpElitebook 1040 G3 Version-
HpElitebook 1040 G4 Firmware Version < 01.44
   HpElitebook 1040 G4 Version-
HpElitebook 820 G3 Firmware Version < 01.58
   HpElitebook 820 G3 Version-
HpElitebook 820 G4 Firmware Version < 01.44
   HpElitebook 820 G4 Version-
HpElitebook 828 G3 Firmware Version < 01.58
   HpElitebook 828 G3 Version-
HpElitebook 828 G4 Firmware Version < 01.44
   HpElitebook 828 G4 Version-
HpElitebook 840 G3 Firmware Version < 01.58
   HpElitebook 840 G3 Version-
HpElitebook 840 G4 Firmware Version < 01.44
   HpElitebook 840 G4 Version-
HpElitebook 848 G3 Firmware Version < 01.58
   HpElitebook 848 G3 Version-
HpElitebook 848 G4 Firmware Version < 01.44
   HpElitebook 848 G4 Version-
HpElitebook 850 G3 Firmware Version < 01.58
   HpElitebook 850 G3 Version-
HpElitebook 850 G4 Firmware Version < 01.44
   HpElitebook 850 G4 Version-
HpElitebook Folio G1 Firmware Version < 01.58
   HpElitebook Folio G1 Version-
HpElitebook X360 1020 G2 Firmware Version < 01.44
   HpElitebook X360 1020 G2 Version-
HpElitebook X360 1030 G2 Firmware Version < 01.44
   HpElitebook X360 1030 G2 Version-
HpProbook 11 G2 Firmware SwEditioneducation Version < 01.58
   HpProbook 11 G2 Version- SwEditioneducation
HpPro X2 612 G2 Firmware Version < 01.44
   HpPro X2 612 G2 Version-
HpProbook 430 G4 Firmware Version < 01.44
   HpProbook 430 G4 Version-
HpProbook 440 G3 Firmware Version < 01.58
   HpProbook 440 G3 Version-
HpProbook 440 G4 Firmware Version < 01.44
   HpProbook 440 G4 Version-
HpProbook 446 G3 Firmware Version < 01.58
   HpProbook 446 G3 Version-
HpProbook 450 G4 Firmware Version < 01.44
   HpProbook 450 G4 Version-
HpProbook 470 G3 Firmware Version < 01.58
   HpProbook 470 G3 Version-
HpProbook 470 G4 Firmware Version < 01.44
   HpProbook 470 G4 Version-
HpProbook 640 G2 Firmware Version < 01.58
   HpProbook 640 G2 Version-
HpProbook 640 G3 Firmware Version < 01.44
   HpProbook 640 G3 Version-
HpProbook 650 G2 Firmware Version < 01.58
   HpProbook 650 G2 Version-
HpProbook 650 G3 Firmware Version < 01.44
   HpProbook 650 G3 Version-
HpProbook X360 11 G2 Firmware SwEditioneducation Version < 1.46
   HpProbook X360 11 G2 Version- SwEditioneducation
HpZbook 14u G4 Firmware Version < 01.44
   HpZbook 14u G4 Version-
HpZbook 15 G3 Firmware Version < 01.58
   HpZbook 15 G3 Version-
HpZbook 15 G4 Firmware Version < 01.44
   HpZbook 15 G4 Version-
HpZbook 15u G3 Firmware Version < 01.58
   HpZbook 15u G3 Version-
HpZbook 15u G4 Firmware Version < 01.44
   HpZbook 15u G4 Version-
HpZbook 17 G3 Firmware Version < 01.58
   HpZbook 17 G3 Version-
HpZbook 17 G4 Firmware Version < 01.44
   HpZbook 17 G4 Version-
HpZbook Studio G3 Firmware Version < 01.58
   HpZbook Studio G3 Version-
HpZbook Studio G4 Firmware Version < 01.44
   HpZbook Studio G4 Version-
HpZbook Studio X2 G4 Firmware Version < 01.44
   HpZbook Studio X2 G4 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.41
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.