CVE-2022-43778

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 12, 2023
Updated: Jan 6, 2025
CWE ID 367

Summary

CVE-2022-43778 is a newly identified vulnerability affecting the HP BIOS of certain HP PC products. This issue involves potential Time-of-Check to Time-of-Use (TOCTOU) bugs, which could allow an attacker to execute arbitrary code, cause denial of service, or disclose sensitive information. The vulnerability arises due to a misalignment between the checking and use of data in the BIOS, leading to security risks during the boot process. The specific HP PC models impacted by this vulnerability have yet to be publicly disclosed. Users are strongly advised to follow HP's security advisories and apply the relevant patches as soon as they become available to mitigate these risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Hp Z8 G4 Workstation Firmware

Affected Vendors

  • HP