6.8

CVE-2022-37019

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution.  HP is releasing firmware updates to mitigate the potential vulnerabilities.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpElite Slice Firmware Version < 00.02.64
   HpElite Slice Version-
HpElitebook 1040 G3 Firmware Version < 01.62
   HpElitebook 1040 G3 Version-
HpElitebook 820 G3 Firmware Version < 01.62
   HpElitebook 820 G3 Version-
HpElitebook 828 G3 Firmware Version < 01.62
   HpElitebook 828 G3 Version-
HpElitebook 840 G3 Firmware Version < 01.62
   HpElitebook 840 G3 Version-
HpElitebook 848 G3 Firmware Version < 01.62
   HpElitebook 848 G3 Version-
HpElitebook 850 G3 Firmware Version < 01.62
   HpElitebook 850 G3 Version-
HpElitebook Folio G1 Firmware Version < 01.62
   HpElitebook Folio G1 Version-
HpMp9 G2 Retail System Firmware Version < 02.63
   HpMp9 G2 Retail System Version-
HpProbook 440 G3 Firmware Version < 1.62
   HpProbook 440 G3 Version-
HpProbook 446 G3 Firmware Version < 1.62
   HpProbook 446 G3 Version-
HpProbook 470 G3 Firmware Version < 1.62
   HpProbook 470 G3 Version-
HpProbook 640 G2 Firmware Version < 1.62
   HpProbook 640 G2 Version-
HpProbook 650 G2 Firmware Version < 1.62
   HpProbook 650 G2 Version-
HpRp9 G1 Retail System Firmware Version < 02.64
   HpRp9 G1 Retail System Version-
HpZ2 Mini G3 Workstation Firmware Version < 01.91
   HpZ2 Mini G3 Workstation Version-
HpZ240 Tower Workstation Firmware Version < 01.91
   HpZ240 Tower Workstation Version-
HpZbook 15 G3 Firmware Version < 1.62
   HpZbook 15 G3 Version-
HpZbook 15u G3 Firmware Version < 1.62
   HpZbook 15u G3 Version-
HpZbook 17 G3 Firmware Version < 1.62
   HpZbook 17 G3 Version-
HpZbook Studio G3 Firmware Version < 1.62
   HpZbook Studio G3 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.324
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.8 2.5 4.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.