CVE-2022-37020

MEDIUM

HP Elite Slice Firmware < 00.02.64 - Buffer Overflow

Title source: rule
STIX 2.1

Description

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.

References (1)

Core 1

Scores

CVSS v3 6.8
EPSS 0.0032
EPSS Percentile 55.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-120
Status published
Products (26)
hp/elite_slice_firmware < 00.02.64
hp/elite_slice_for_meeting_rooms_firmware < 00.02.64
hp/elitebook_1040_g3_firmware < 01.62
hp/elitebook_820_g3_firmware < 01.62
hp/elitebook_828_g3_firmware < 01.62
hp/elitebook_840_g3_firmware < 01.62
hp/elitebook_848_g3_firmware < 01.62
hp/elitebook_850_g3_firmware < 01.62
hp/elitebook_folio_g1_firmware < 01.62
hp/elitedesk_800_35w_g2_desktop_mini_pc_firmware < 00.02.63
... and 16 more
Published Jun 10, 2024
Tracked Since Feb 18, 2026