7

CVE-2022-43779

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ 348 G4 Firmware Version < f.65
   Hp ≫ 348 G4 Version -
Hp ≫ 260 G2 Desktop Mini Firmware Version < 2.26
   Hp ≫ 260 G2 Desktop Mini Version -
Hp ≫ 218 Pro G5 Mt Firmware Version < f15
   Hp ≫ 218 Pro G5 Mt Version -
Hp ≫ 260 G3 Desktop Mini Firmware Version < 02.20.00
   Hp ≫ 260 G3 Desktop Mini Version -
Hp ≫ 260 G4 Desktop Mini Firmware Version < 02.12.00
   Hp ≫ 260 G4 Desktop Mini Version -
Hp ≫ 280 G3 Microtower Pc Firmware Version < 02.02.40
   Hp ≫ 280 G3 Microtower Pc Version -
Hp ≫ 280 G3 Pci Microtower Pc Firmware Version < 02.02.40
   Hp ≫ 280 G3 Pci Microtower Pc Version -
Hp ≫ 288 Pro G3 Microtower Pc Firmware Version < 00.02.40
   Hp ≫ 288 Pro G3 Microtower Pc Version -
Hp ≫ 290 G1 Microtower Firmware Version < 00.02.40
   Hp ≫ 290 G1 Microtower Version -
Hp ≫ Desktop Pro 300 G3 Firmware Version < f15
   Hp ≫ Desktop Pro 300 G3 Version -
Hp ≫ Desktop Pro A 300 G3 Firmware Version < f12
   Hp ≫ Desktop Pro A 300 G3 Version -
Hp ≫ Desktop Pro A G2 Firmware Version < f.11
   Hp ≫ Desktop Pro A G2 Version -
Hp ≫ Desktop Pro A G3 Firmware Version < f12
   Hp ≫ Desktop Pro A G3 Version -
Hp ≫ Desktop Pro G3 Firmware Version < f15
   Hp ≫ Desktop Pro G3 Version -
Hp ≫ Desktop Pro G3 Microtower Firmware Version < f15
   Hp ≫ Desktop Pro G3 Microtower Version -
Hp ≫ Desktop Pro Microtower Firmware Version < 00.02.40
   Hp ≫ Desktop Pro Microtower Version -
Hp ≫ Zhan 86 Pro G1 Microtower Firmware Version < 00.02.40
   Hp ≫ Zhan 86 Pro G1 Microtower Version -
Hp ≫ Rp2 Retail System 2000 Firmware Version < 2.24
   Hp ≫ Rp2 Retail System 2000 Version -
Hp ≫ Rp2 Retail System 2020 Firmware Version < 2.24
   Hp ≫ Rp2 Retail System 2020 Version -
Hp ≫ Rp2 Retail System 2030 Firmware Version < 2.24
   Hp ≫ Rp2 Retail System 2030 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.034
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

https://support.hp.com/us-en/document/ish_7394557-7394585-16/hpsbhf03829
Patch
Vendor Advisory