cbcvebase.
CVE-2022-31638
published 2023-06-13

CVE-2022-31638: Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code…

high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

Affected

400 ranges· showing 25
VendorProductVersion rangeFixed in
hpdragonfly_folio_13.5_inch_g3_2-in-1_notebook_pc_firmware<= 0.10.103
hpelite_dragonfly_13.5_inch_g3_notebook_pc_firmware<= 01.03.01
hpelite_dragonfly_firmware<= 01.21.01
hpelite_dragonfly_g2_firmware<= 01.09.10
hpelite_dragonfly_max_firmware<= 01.09.10
hpelite_mini_600_g9_desktop_pc_firmware<= 02.05.00
hpelite_mini_800_g9_desktop_pc_firmware<= 02.05.00
hpelite_sff_600_g9_desktop_pc_firmware<= 02.05.01
hpelite_sff_800_g9_desktop_pc_firmware<= 02.05.01
hpelite_slice_firmware<= 2.58
hpelite_slice_for_meeting_rooms_firmware<= 2.58
hpelite_slice_g2_audio_ready_with_zoom_rooms_firmware<= 2.58
hpelite_slice_g2_partner_ready_with_microsoft_teams_rooms_firmware<= 2.58
hpelite_slice_g2_with_intel_unite_firmware<= 2.58
hpelite_slice_g2_with_microsoft_teams_rooms_firmware<= 2.58
hpelite_slice_g2_with_zoom_rooms_firmware<= 2.58
hpelite_tower_600_g9_desktop_pc_firmware<= 02.05.01
hpelite_tower_680_g9_desktop_pc_firmware<= 02.05.01
hpelite_tower_800_g9_desktop_pc_firmware<= 02.05.01
hpelite_tower_880_g9_desktop_pc_firmware<= 02.05.01
hpelite_x2_1012_g1_firmware<= 1.57
hpelite_x2_1012_g1_tablet_firmware<= 1.57
hpelite_x2_1012_g1_tablet_with_travel_keyboard_firmware<= 1.57
hpelite_x2_1012_g2_firmware<= 1.43
hpelite_x2_1013_g3_firmware<= 01.21.01