CVE-2022-37020

EUVD-2022-39677
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
CISA-ADPADP
6.8 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
Affected Products (NVD)
VendorProductVersion
hpelite_slice_firmware
𝑥
< 00.02.64
hpelite_slice_for_meeting_rooms_firmware
𝑥
< 00.02.64
hpelitebook_1040_g3_firmware
𝑥
< 01.62
hpelitebook_820_g3_firmware
𝑥
< 01.62
hpelitebook_828_g3_firmware
𝑥
< 01.62
hpelitebook_840_g3_firmware
𝑥
< 01.62
hpelitebook_848_g3_firmware
𝑥
< 01.62
hpelitebook_850_g3_firmware
𝑥
< 01.62
hpelitebook_folio_g1_firmware
𝑥
< 01.62
hpelitedesk_800_35w_g2_desktop_mini_pc_firmware
𝑥
< 00.02.63
hpelitedesk_800_65w_g2_desktop_mini_pc_firmware
𝑥
< 00.02.63
hpmp9_g2_retail_system_firmware
𝑥
< 02.63
hpprobook_440_g3_firmware
𝑥
< 1.62
hpprobook_446_g3_firmware
𝑥
< 1.62
hpprobook_470_g3_firmware
𝑥
< 1.62
hpprobook_640_g2_firmware
𝑥
< 1.62
hpprobook_650_g2_firmware
𝑥
< 1.62
hprp9_g1_retail_system_firmware
𝑥
< 02.64
hpz2_mini_g3_workstation_firmware
𝑥
< 01.91
hpz238_microtower_workstation_firmware
𝑥
< 01.91
hpz240_small_form_factor_workstation_firmware
𝑥
< 01.91
hpz240_tower_workstation_firmware
𝑥
< 01.91
hpzbook_15_g3_firmware
𝑥
< 1.62
hpzbook_15u_g3_firmware
𝑥
< 1.62
hpzbook_17_g3_firmware
𝑥
< 1.62
hpzbook_studio_g3_firmware
𝑥
< 1.62
𝑥
= Vulnerable software versions