CVE-2022-23958
published 2022-03-02CVE-2022-23958: Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.5th percentile
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | probook_440_g8_firmware | < 01.08.11 | 01.08.11 |
| hp | prodesk_405_g6_small_form_factor_firmware | < 02.07.10 | 02.07.10 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Sentinelone
Another Brick in the Wall: Uncovering SMM Vulnerabilities in HP Firmware
blogs_sentinelone·2022-03-10·CVSS 5.5
CVE-2022-23956 [MEDIUM] Another Brick in the Wall: Uncovering SMM Vulnerabilities in HP Firmware
By Assaf Carlsbad & Itai Liba
## Executive Summary
- SentinelLabs has discovered 6 high severity flaws in HP’s UEFI firmware impacting HP laptops and desktops.
- Attackers may exploit these vulnerabilities to locally escalate to SMM privileges.
- SentinelLabs findings were proactively reported to HP on Aug 18, 2021, and are tracked as:
- CVE-2022-23956, marked with a CVSS score of 8.2
- CVE-2022-23953, marked with a CVSS score of 7.9
- CVE-2022-23954, marked with a CVSS score of 7.9
- CVE-2022-23955, marked with a CVSS score of 7.9
- CVE-2022-23957, marked with a CVSS score of 7.9
- CVE-2022-23958, marked with a CVSS score of 7.9
- HP has released a security update to its customers to address these vulnerabilities.
- At this time, SentinelOne has not discovered evidence of in-the-wild
Sentinelone
Another Brick in the Wall: Uncovering SMM Vulnerabilities in HP Firmware
blogs_sentinelone·2022-03-10·CVSS 5.5
CVE-2022-23956 [MEDIUM] Another Brick in the Wall: Uncovering SMM Vulnerabilities in HP Firmware
## Another Brick in the Wall: Uncovering SMM Vulnerabilities in HP Firmware
By Assaf Carlsbad & Itai Liba
## Executive Summary
SentinelLabs has discovered 6 high severity flaws in HP’s UEFI firmware impacting HP laptops and desktops.
Attackers may exploit these vulnerabilities to locally escalate to SMM privileges.
CVE-2022-23956, marked with a CVSS score of 8.2
CVE-2022-23953, marked with a CVSS score of 7.9
CVE-2022-23954, marked with a CVSS score of 7.9
CVE-2022-23955, marked with a CVSS score of 7.9
CVE-2022-23957, marked with a CVSS score of 7.9
CVE-2022-23958, marked with a CVSS score of 7.9
HP has released a security update to its customers to address these vulnerabilities.
At this time, SentinelOne has not discovered evidence of in-the-wild abuse.
Hello and welcome bac
2022-03-02
Published