CVE-2022-31636

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 13, 2023
Updated: Jan 3, 2025
CWE ID 367

Summary

CVE-2022-31636 is a newly identified vulnerability affecting the BIOS of certain HP PC products. This issue involves potential time-of-check to time-of-use (TOCTOU) inconsistencies, which could permit an attacker to execute arbitrary code, escalate privileges, cause denial of service, or disclose sensitive information. The vulnerability arises due to the BIOS's failure to properly manage input validation during critical operations. HP is actively working on releasing patches to mitigate the risk associated with this issue. Users are advised to apply these updates promptly to secure their systems against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Hp Z8 G4 Workstation Firmware

Affected Vendors

  • HP