HIGH · 7.0

CVE-2022-27538

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information ...

Vulnerability Description

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.

CVSS Score

7.0

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HpDragonfly Folio G3 2-In-1 Firmware< 01.03.01
HpDragonfly Folio G3 2-In-1-
HpElite Dragonfly Firmware< 01.22.00
HpElite Dragonfly-
HpElite Dragonfly G3 Firmware< 01.04.00
HpElite Dragonfly G3-
HpElite Dragonfly G2 Firmware< 01.11.00
HpElite Dragonfly G2-
HpElite Dragonfly Max Firmware< 01.11.00
HpElite Dragonfly Max-
HpElite X2 1013 G3 Firmware< 01.22.00
HpElite X2 1013 G3-
HpElite X2 G4 Firmware< 01.22.00
HpElite X2 G4-
HpElite X2 G8 Tablet Firmware< 01.11.00
HpElite X2 G8 Tablet-
HpElite X360 1040 G9 2-In-1 Firmware< 01.04.02
HpElite X360 1040 G9 2-In-1-
HpElitebook 1040 G9 Firmware< 01.04.02
HpElitebook 1040 G9-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-27538?

CVE-2022-27538 is a vulnerability with a CVSS score of 7.0 (HIGH). A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information ...

How severe is CVE-2022-27538?

CVE-2022-27538 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-27538?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Dragonfly Folio G3 2-In-1 Firmware, Hp Dragonfly Folio G3 2-In-1, Hp Elite Dragonfly Firmware, Hp Elite Dragonfly, Hp Elite Dragonfly G3 Firmware.