CVE-2022-37018

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/12/2022
Last modified:
29/04/2025

Description

A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hp:z1_g3_firmware:*:*:*:*:*:*:*:* 01.33 (excluding)
cpe:2.3:h:hp:z1_g3:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:z2_mini_g3_firmware:*:*:*:*:*:*:*:* 01.85 (excluding)
cpe:2.3:h:hp:z2_mini_g3:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:z238_microtower_firmware:*:*:*:*:*:*:*:* 01.85 (excluding)
cpe:2.3:h:hp:z238_microtower:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:z240_sff_firmware:*:*:*:*:*:*:*:* 01.85 (excluding)
cpe:2.3:h:hp:z240_sff:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:z240_tower_firmware:*:*:*:*:*:*:*:* 01.85 (excluding)
cpe:2.3:h:hp:z240_tower:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:engage_one_aio_system_firmware:*:*:*:*:*:*:*:* 02.44 (excluding)
cpe:2.3:h:hp:engage_one_aio_system:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:mp9_g2_retail_system_firmware:*:*:*:*:*:*:*:* 02.59 (excluding)
cpe:2.3:h:hp:mp9_g2_retail_system:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:rp9_g1_retail_system_firmware:*:*:*:*:*:*:*:* 02.59 (excluding)