CVE-2022-31636

CWE-3673 documents3 sources
Severity
7.8HIGH
EPSS
0.2%
top 61.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13

Description

Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 1.1 | Impact: 6.0

Affected Packages404 packages

CVEListV5hp_inc./hp_pc_biosSee HP Security Bulletin reference for affected versions.
NVDhp/elite_slice2.58

🔴Vulnerability Details

2
CVEList
CVE-2022-31636: Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitra2023-06-13
GHSA
GHSA-9m5f-j2g3-2fcr: Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitra2023-06-13
CVE-2022-31636 (HIGH CVSS 7.8) | Potential time-of-check to time-of- | cvebase.io