Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43779


A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 7.0, requiring local system access to exploit but requires specific conditions to be met without requiring user interaction requiring only low-level privileges . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 50 products from hp, from hp, from hp and 47 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2023, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2023-02-12T04:15:16.060

Last Modified

2025-03-25T21:15:37.933

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.0 (HIGH)

Weaknesses
  • Type: Primary
    CWE-367
  • Type: Secondary
    CWE-367

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hp 348_g4_firmware < f.65 Yes
Hardware hp 348_g4 - No
Operating System hp 260_g2_desktop_mini_firmware < 2.26 Yes
Hardware hp 260_g2_desktop_mini - No
Operating System hp 218_pro_g5_mt_firmware < f15 Yes
Hardware hp 218_pro_g5_mt - No
Operating System hp 260_g3_desktop_mini_firmware < 02.20.00 Yes
Hardware hp 260_g3_desktop_mini - No
Operating System hp 260_g4_desktop_mini_firmware < 02.12.00 Yes
Hardware hp 260_g4_desktop_mini - No
Operating System hp 280_g3_microtower_pc_firmware < 02.02.40 Yes
Hardware hp 280_g3_microtower_pc - No
Operating System hp 280_g3_pci_microtower_pc_firmware < 02.02.40 Yes
Hardware hp 280_g3_pci_microtower_pc - No
Operating System hp 288_pro_g3_microtower_pc_firmware < 00.02.40 Yes
Hardware hp 288_pro_g3_microtower_pc - No
Operating System hp 290_g1_microtower_firmware < 00.02.40 Yes
Hardware hp 290_g1_microtower - No
Operating System hp desktop_pro_300_g3_firmware < f15 Yes
Hardware hp desktop_pro_300_g3 - No
Operating System hp desktop_pro_a_300_g3_firmware < f12 Yes
Hardware hp desktop_pro_a_300_g3 - No
Operating System hp desktop_pro_a_g2_firmware < f.11 Yes
Hardware hp desktop_pro_a_g2 - No
Operating System hp desktop_pro_a_g2_microtower_firmware < f.11 Yes
Hardware hp desktop_pro_a_g2_microtower - No
Operating System hp desktop_pro_a_g3_firmware < f12 Yes
Hardware hp desktop_pro_a_g3 - No
Operating System hp desktop_pro_a_g3_microtower_firmware < f12 Yes
Hardware hp desktop_pro_a_g3_microtower - No
Operating System hp desktop_pro_g3_firmware < f15 Yes
Hardware hp desktop_pro_g3 - No
Operating System hp desktop_pro_g3_microtower_firmware < f15 Yes
Hardware hp desktop_pro_g3_microtower - No
Operating System hp desktop_pro_microtower_firmware < 00.02.40 Yes
Hardware hp desktop_pro_microtower - No
Operating System hp zhan_66_pro_a_g1_microtower_firmware < f.11 Yes
Hardware hp zhan_66_pro_a_g1_microtower - No
Operating System hp zhan_66_pro_a_g1_r_microtower_firmware < f12 Yes
Hardware hp zhan_66_pro_a_g1_r_microtower - No
Operating System hp zhan_66_pro_g1_r_microtower_firmware < f15 Yes
Hardware hp zhan_66_pro_g1_r_microtower - No
Operating System hp zhan_86_pro_g1_microtower_firmware < 00.02.40 Yes
Hardware hp zhan_86_pro_g1_microtower - No
Operating System hp rp2_retail_system_2000_firmware < 2.24 Yes
Hardware hp rp2_retail_system_2000 - No
Operating System hp rp2_retail_system_2020_firmware < 2.24 Yes
Hardware hp rp2_retail_system_2020 - No
Operating System hp rp2_retail_system_2030_firmware < 2.24 Yes
Hardware hp rp2_retail_system_2030 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For hp's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.