Vulnerability Description
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Zcentral 4R Workstation Firmware | <= 1.24 |
| Hp | Zcentral 4R Workstation | - |
| Hp | Z1 All-In-One G3 Workstation Firmware | <= 1.33 |
| Hp | Z1 All-In-One G3 Workstation | - |
| Hp | Elitebook 725 G4 Firmware | <= 1.42 |
| Hp | Elitebook 725 G4 | - |
| Hp | Elitebook 745 G4 Firmware | <= 1.42 |
| Hp | Elitebook 745 G4 | - |
| Hp | Elitebook 755 G4 Firmware | <= 1.42 |
| Hp | Elitebook 755 G4 | - |
| Hp | Probook 645 G3 Firmware | <= 1.42 |
| Hp | Probook 645 G3 | - |
| Hp | Probook 655 G3 Firmware | <= 1.42 |
| Hp | Probook 655 G3 | - |
| Hp | Mt43 Mobile Thin Client Firmware | <= 1.42 |
| Hp | Mt43 Mobile Thin Client | - |
| Hp | Elite X2 1012 G2 Firmware | <= 1.43 |
| Hp | Elite X2 1012 G2 | - |
| Hp | Elitebook 1040 G4 Firmware | <= 1.43 |
| Hp | Elitebook 1040 G4 | - |
Related Weaknesses (CWE)
References
- https://support.hp.com/us-en/document/ish_7709808-7709835-16/hpsbhf03835ExploitVendor Advisory
- https://support.hp.com/us-en/document/ish_7709808-7709835-16/hpsbhf03835ExploitVendor Advisory
- https://support.hp.com/us-en/document/ish_7709808-7709835-16/hpsbhf03835ExploitVendor Advisory
FAQ
What is CVE-2022-43778?
CVE-2022-43778 is a vulnerability with a CVSS score of 7.8 (HIGH). Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and informat...
How severe is CVE-2022-43778?
CVE-2022-43778 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-43778?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Zcentral 4R Workstation Firmware, Hp Zcentral 4R Workstation, Hp Z1 All-In-One G3 Workstation Firmware, Hp Z1 All-In-One G3 Workstation, Hp Elitebook 725 G4 Firmware.