Vulnerability Description
Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Acer | Aspire A315-22G Firmware | - |
| Acer | Aspire A315-22G | - |
| Acer | Aspire A115-21 Firmware | - |
| Acer | Aspire A115-21 | - |
| Acer | Aspire A315-22 Firmware | - |
| Acer | Aspire A315-22 | - |
| Acer | Extensa Ex215-21 Firmware | - |
| Acer | Extensa Ex215-21 | - |
| Acer | Extensa Ex215-21G Firmware | - |
| Acer | Extensa Ex215-21G | - |
Related Weaknesses (CWE)
References
- https://community.acer.com/en/kb/articles/15520-security-vulnerability-regardingVendor Advisory
- https://community.acer.com/en/kb/articles/15520-security-vulnerability-regardingVendor Advisory
FAQ
What is CVE-2022-4020?
CVE-2022-4020 is a vulnerability with a CVSS score of 8.1 (HIGH). Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.
How severe is CVE-2022-4020?
CVE-2022-4020 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-4020?
Check the references section above for vendor advisories and patch information. Affected products include: Acer Aspire A315-22G Firmware, Acer Aspire A315-22G, Acer Aspire A115-21 Firmware, Acer Aspire A115-21, Acer Aspire A315-22 Firmware.