HIGH · 7.0

CVE-2022-43779

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial o...

Vulnerability Description

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability.

CVSS Score

7.0

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Hp348 G4 Firmware< f.65
Hp348 G4-
Hp260 G2 Desktop Mini Firmware< 2.26
Hp260 G2 Desktop Mini-
Hp218 Pro G5 Mt Firmware< f15
Hp218 Pro G5 Mt-
Hp260 G3 Desktop Mini Firmware< 02.20.00
Hp260 G3 Desktop Mini-
Hp260 G4 Desktop Mini Firmware< 02.12.00
Hp260 G4 Desktop Mini-
Hp280 G3 Microtower Pc Firmware< 02.02.40
Hp280 G3 Microtower Pc-
Hp280 G3 Pci Microtower Pc Firmware< 02.02.40
Hp280 G3 Pci Microtower Pc-
Hp288 Pro G3 Microtower Pc Firmware< 00.02.40
Hp288 Pro G3 Microtower Pc-
Hp290 G1 Microtower Firmware< 00.02.40
Hp290 G1 Microtower-
HpDesktop Pro 300 G3 Firmware< f15
HpDesktop Pro 300 G3-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-43779?

CVE-2022-43779 is a vulnerability with a CVSS score of 7.0 (HIGH). A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial o...

How severe is CVE-2022-43779?

CVE-2022-43779 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-43779?

Check the references section above for vendor advisories and patch information. Affected products include: Hp 348 G4 Firmware, Hp 348 G4, Hp 260 G2 Desktop Mini Firmware, Hp 260 G2 Desktop Mini, Hp 218 Pro G5 Mt Firmware.