A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability.

Project Subscriptions

Vendors Products
218 Pro G5 Mt Subscribe
218 Pro G5 Mt Firmware Subscribe
260 G2 Desktop Mini Subscribe
260 G2 Desktop Mini Firmware Subscribe
260 G3 Desktop Mini Subscribe
260 G3 Desktop Mini Firmware Subscribe
260 G4 Desktop Mini Subscribe
260 G4 Desktop Mini Firmware Subscribe
280 G3 Microtower Pc Subscribe
280 G3 Microtower Pc Firmware Subscribe
280 G3 Pci Microtower Pc Subscribe
280 G3 Pci Microtower Pc Firmware Subscribe
288 Pro G3 Microtower Pc Subscribe
288 Pro G3 Microtower Pc Firmware Subscribe
290 G1 Microtower Subscribe
290 G1 Microtower Firmware Subscribe
348 G4 Firmware Subscribe
Desktop Pro 300 G3 Subscribe
Desktop Pro 300 G3 Firmware Subscribe
Desktop Pro A 300 G3 Subscribe
Desktop Pro A 300 G3 Firmware Subscribe
Desktop Pro A G2 Subscribe
Desktop Pro A G2 Firmware Subscribe
Desktop Pro A G2 Microtower Subscribe
Desktop Pro A G2 Microtower Firmware Subscribe
Desktop Pro A G3 Subscribe
Desktop Pro A G3 Firmware Subscribe
Desktop Pro A G3 Microtower Subscribe
Desktop Pro A G3 Microtower Firmware Subscribe
Desktop Pro G3 Subscribe
Desktop Pro G3 Firmware Subscribe
Desktop Pro G3 Microtower Subscribe
Desktop Pro G3 Microtower Firmware Subscribe
Desktop Pro Microtower Subscribe
Desktop Pro Microtower Firmware Subscribe
Rp2 Retail System 2000 Subscribe
Rp2 Retail System 2000 Firmware Subscribe
Rp2 Retail System 2020 Subscribe
Rp2 Retail System 2020 Firmware Subscribe
Rp2 Retail System 2030 Subscribe
Rp2 Retail System 2030 Firmware Subscribe
Zhan 66 Pro A G1 Microtower Subscribe
Zhan 66 Pro A G1 Microtower Firmware Subscribe
Zhan 66 Pro A G1 R Microtower Subscribe
Zhan 66 Pro A G1 R Microtower Firmware Subscribe
Zhan 66 Pro G1 R Microtower Subscribe
Zhan 66 Pro G1 R Microtower Firmware Subscribe
Zhan 86 Pro G1 Microtower Subscribe
Zhan 86 Pro G1 Microtower Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-46749 A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 25 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2025-03-25T20:44:42.683Z

Reserved: 2022-10-26T14:39:32.656Z

Link: CVE-2022-43779

cve-icon Vulnrichment

Updated: 2024-08-03T13:40:06.295Z

cve-icon NVD

Status : Modified

Published: 2023-02-12T04:15:16.060

Modified: 2025-03-25T21:15:37.933

Link: CVE-2022-43779

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses