CVE-2022-27540
published 2024-06-28CVE-2022-27540: A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code…
PriorityP339high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
EPSS
0.12%
2.0th percentile
A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
Affected
355 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | dragonfly_folio_13.5_inch_g3_2-in-1_notebook_pc_firmware | < 01.07.00 | 01.07.00 |
| hp | elite_dragonfly_13.5_inch_g3_notebook_pc_firmware | < 01.07.00 | 01.07.00 |
| hp | elite_dragonfly_firmware | < 01.26.00 | 01.26.00 |
| hp | elite_dragonfly_g2_firmware | < 01.11.00 | 01.11.00 |
| hp | elite_dragonfly_max_firmware | < 01.11.00 | 01.11.00 |
| hp | elite_mini_600_g9_desktop_pc_firmware | < 02.10.04 | 02.10.04 |
| hp | elite_mini_800_g9_desktop_pc_firmware | < 02.10.04 | 02.10.04 |
| hp | elite_mt645_g7_mobile_thin_client_firmware | < 01.10.01 | 01.10.01 |
| hp | elite_sff_600_g9_desktop_pc_firmware | < 02.10.05 | 02.10.05 |
| hp | elite_sff_800_g9_desktop_pc_firmware | < 02.10.05 | 02.10.05 |
| hp | elite_slice_g2_audio_ready_with_zoom_rooms_firmware | < 2.64 | 2.64 |
| hp | elite_slice_g2_partner_ready_with_microsoft_teams_rooms_firmware | < 2.64 | 2.64 |
| hp | elite_slice_g2_with_intel_unite_firmware | < 2.64 | 2.64 |
| hp | elite_slice_g2_with_microsoft_teams_rooms_firmware | < 2.64 | 2.64 |
| hp | elite_slice_g2_with_zoom_rooms_firmware | < 2.64 | 2.64 |
| hp | elite_tower_600_g9_desktop_pc_firmware | < 02.10.05 | 02.10.05 |
| hp | elite_tower_680_g9_desktop_pc_firmware | < 02.10.05 | 02.10.05 |
| hp | elite_tower_800_g9_desktop_pc_firmware | < 02.10.05 | 02.10.05 |
| hp | elite_tower_880_g9_desktop_pc_firmware | < 02.10.05 | 02.10.05 |
| hp | elite_x2_1012_g1_firmware | < 1.6 | 1.6 |
| hp | elite_x2_1012_g1_tablet_firmware | — | — |
| hp | elite_x2_1012_g1_tablet_with_travel_keyboard_firmware | — | — |
| hp | elite_x2_1012_g2_firmware | — | — |
| hp | elite_x2_1013_g3_firmware | — | — |
| hp | elite_x2_g4_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
HP PC BIOS toctou
vuldb·2026-05-04·CVSS 7.8
CVE-2022-27540 [HIGH] HP PC BIOS toctou
A vulnerability categorized as critical has been discovered in HP PC BIOS. This affects an unknown function. The manipulation results in time-of-check time-of-use.
This vulnerability is known as CVE-2022-27540. Access to the local network is required for this attack. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
GHSA-gfx2-f362-7f24: A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbit
ghsa_unreviewed·2024-06-29
CVE-2022-27540 [HIGH] CWE-367 GHSA-gfx2-f362-7f24: A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbit
A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-28
Published