Vulnerability Description
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Dragonfly Folio G3 2-In-1 Firmware | < 01.03.01 |
| Hp | Dragonfly Folio G3 2-In-1 | - |
| Hp | Elite Dragonfly Firmware | < 01.22.00 |
| Hp | Elite Dragonfly | - |
| Hp | Elite Dragonfly G3 Firmware | < 01.04.00 |
| Hp | Elite Dragonfly G3 | - |
| Hp | Elite Dragonfly G2 Firmware | < 01.11.00 |
| Hp | Elite Dragonfly G2 | - |
| Hp | Elite Dragonfly Max Firmware | < 01.11.00 |
| Hp | Elite Dragonfly Max | - |
| Hp | Elite X2 1013 G3 Firmware | < 01.22.00 |
| Hp | Elite X2 1013 G3 | - |
| Hp | Elite X2 G4 Firmware | < 01.22.00 |
| Hp | Elite X2 G4 | - |
| Hp | Elite X2 G8 Tablet Firmware | < 01.11.00 |
| Hp | Elite X2 G8 Tablet | - |
| Hp | Elite X360 1040 G9 2-In-1 Firmware | < 01.04.02 |
| Hp | Elite X360 1040 G9 2-In-1 | - |
| Hp | Elitebook 1040 G9 Firmware | < 01.04.02 |
| Hp | Elitebook 1040 G9 | - |
Related Weaknesses (CWE)
References
- https://support.hp.com/us-en/document/ish_7387020-7387107-16/hpsbhf03827PatchVendor Advisory
- https://support.hp.com/us-en/document/ish_7387020-7387107-16/hpsbhf03827PatchVendor Advisory
FAQ
What is CVE-2022-27538?
CVE-2022-27538 is a vulnerability with a CVSS score of 7.0 (HIGH). A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information ...
How severe is CVE-2022-27538?
CVE-2022-27538 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-27538?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Dragonfly Folio G3 2-In-1 Firmware, Hp Dragonfly Folio G3 2-In-1, Hp Elite Dragonfly Firmware, Hp Elite Dragonfly, Hp Elite Dragonfly G3 Firmware.