CVE-2022-27540

A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
Configurations

No configuration.

History

21 Nov 2024, 06:55

Type Values Removed Values Added
References () https://support.hp.com/us-en/document/ish_10810714-10810745-16/hpsbhf03948 - () https://support.hp.com/us-en/document/ish_10810714-10810745-16/hpsbhf03948 -

22 Aug 2024, 15:35

Type Values Removed Values Added
CWE CWE-367
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

01 Jul 2024, 12:37

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una posible vulnerabilidad de tiempo de verificación a tiempo de uso (TOCTOU) en el BIOS de HP para ciertos productos de PC HP, que podría permitir la ejecución de código arbitrario, denegación de servicio y divulgación de información. HP está lanzando actualizaciones de BIOS para mitigar la vulnerabilidad potencial.

28 Jun 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-28 19:15

Updated : 2024-11-21 06:55


NVD link : CVE-2022-27540

Mitre link : CVE-2022-27540

CVE.ORG link : CVE-2022-27540


JSON object : View

Products Affected

No product.

CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition