CVE-2022-27537
📋 TL;DR
This CVE describes vulnerabilities in the system BIOS of certain HP PC products that could allow attackers to execute arbitrary code, escalate privileges, cause denial of service, or disclose sensitive information. The vulnerability affects HP PC users with vulnerable BIOS versions. Attackers could potentially compromise the system firmware itself.
💻 Affected Systems
- Certain HP PC products (specific models not listed in provided references)
📦 What is this software?
Dragonfly Folio G3 2 In 1 Firmware by Hp
View all CVEs affecting Dragonfly Folio G3 2 In 1 Firmware →
Elite X360 1040 G9 2 In 1 Firmware by Hp
View all CVEs affecting Elite X360 1040 G9 2 In 1 Firmware →
Elitedesk 705 G4 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 705 G4 Desktop Mini Firmware →
Elitedesk 705 G4 Microtower Firmware by Hp
View all CVEs affecting Elitedesk 705 G4 Microtower Firmware →
Elitedesk 705 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 705 G4 Small Form Factor Firmware →
Elitedesk 705 G4 Workstation Firmware by Hp
View all CVEs affecting Elitedesk 705 G4 Workstation Firmware →
Elitedesk 705 G5 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 705 G5 Desktop Mini Firmware →
Elitedesk 705 G5 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 705 G5 Small Form Factor Firmware →
Elitedesk 800 35w G2 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 35w G2 Desktop Mini Firmware →
Elitedesk 800 35w G3 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 35w G3 Desktop Mini Firmware →
Elitedesk 800 35w G4 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 35w G4 Desktop Mini Firmware →
Elitedesk 800 65w G2 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 65w G2 Desktop Mini Firmware →
Elitedesk 800 65w G3 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 65w G3 Desktop Mini Firmware →
Elitedesk 800 65w G4 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 65w G4 Desktop Mini Firmware →
Elitedesk 800 95w G4 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 95w G4 Desktop Mini Firmware →
Elitedesk 800 G2 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G2 Small Form Factor Firmware →
Elitedesk 800 G3 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G3 Small Form Factor Firmware →
Elitedesk 800 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G4 Small Form Factor Firmware →
Elitedesk 800 G4 Workstation Firmware by Hp
View all CVEs affecting Elitedesk 800 G4 Workstation Firmware →
Elitedesk 800 G5 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 G5 Desktop Mini Firmware →
Elitedesk 800 G5 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G5 Small Form Factor Firmware →
Elitedesk 800 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 G6 Desktop Mini Firmware →
Elitedesk 800 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G6 Small Form Factor Firmware →
Elitedesk 800 G8 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 G8 Desktop Mini Firmware →
Elitedesk 800 G8 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G8 Small Form Factor Firmware →
Elitedesk 805 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 805 G6 Desktop Mini Firmware →
Elitedesk 805 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 805 G6 Small Form Factor Firmware →
Elitedesk 805 G8 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 805 G8 Desktop Mini Firmware →
Elitedesk 805 G8 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 805 G8 Small Form Factor Firmware →
Eliteone 1000 G1 23.8 In All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G1 23.8 In All In One Business Firmware →
Eliteone 1000 G1 23.8 In Touch All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G1 23.8 In Touch All In One Business Firmware →
Eliteone 1000 G1 27 In 4k Uhd All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G1 27 In 4k Uhd All In One Business Firmware →
Eliteone 1000 G1 34 In Curved All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G1 34 In Curved All In One Business Firmware →
Eliteone 1000 G2 23.8 In All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 23.8 In All In One Business Firmware →
Eliteone 1000 G2 23.8 In Touch All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 23.8 In Touch All In One Business Firmware →
Eliteone 1000 G2 27 In 4k Uhd All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 27 In 4k Uhd All In One Business Firmware →
Eliteone 1000 G2 34 In Curved All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 34 In Curved All In One Business Firmware →
Eliteone 800 G2 23 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G2 23 Inch Non Touch All In One Firmware →
Eliteone 800 G2 23 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G2 23 Inch Non Touch All In One Firmware →
Eliteone 800 G2 23 Inch Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G2 23 Inch Touch All In One Firmware →
Eliteone 800 G2 23 Inch Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G2 23 Inch Touch All In One Firmware →
Eliteone 800 G3 23.8 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Inch Non Touch All In One Firmware →
Eliteone 800 G3 23.8 Inch Non Touch Gpu All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Inch Non Touch Gpu All In One Firmware →
Eliteone 800 G3 23.8 Inch Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Inch Touch All In One Firmware →
Eliteone 800 G3 23.8 Inch Touch Gpu All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Inch Touch Gpu All In One Firmware →
Eliteone 800 G3 23.8 Non Touch All In One Business Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Non Touch All In One Business Firmware →
Eliteone 800 G4 23.8 In All In One Business Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 In All In One Business Firmware →
Eliteone 800 G4 23.8 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Non Touch All In One Firmware →
Eliteone 800 G4 23.8 Inch Non Touch Gpu All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Non Touch Gpu All In One Firmware →
Eliteone 800 G4 23.8 Inch Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Touch All In One Firmware →
Eliteone 800 G4 23.8 Inch Touch Gpu All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Touch Gpu All In One Firmware →
Eliteone 800 G5 23.8 In All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G5 23.8 In All In One Firmware →
Eliteone 800 G5 23.8 Inch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G5 23.8 Inch All In One Firmware →
Eliteone 800 G6 24 All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G6 24 All In One Firmware →
Eliteone 800 G6 27 All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G6 27 All In One Firmware →
Eliteone 800 G8 24 All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G8 24 All In One Firmware →
Eliteone 800 G8 27 All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G8 27 All In One Firmware →
Eliteone 840 23.8 Inch G9 All In One Firmware by Hp
View all CVEs affecting Eliteone 840 23.8 Inch G9 All In One Firmware →
Engage Flex Mini Retail System Firmware by Hp
View all CVEs affecting Engage Flex Mini Retail System Firmware →
Engage Flex Pro C Retail System Firmware by Hp
View all CVEs affecting Engage Flex Pro C Retail System Firmware →
Engage Flex Pro Retail System Firmware by Hp
View all CVEs affecting Engage Flex Pro Retail System Firmware →
Engage Go 10 Mobile System Firmware by Hp
View all CVEs affecting Engage Go 10 Mobile System Firmware →
Engage One Pro Aio System Firmware by Hp
View all CVEs affecting Engage One Pro Aio System Firmware →
Prodesk 400 G3 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 400 G3 Desktop Mini Firmware →
Prodesk 400 G4 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 400 G4 Desktop Mini Firmware →
Prodesk 400 G4 Microtower Firmware by Hp
View all CVEs affecting Prodesk 400 G4 Microtower Firmware →
Prodesk 400 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 400 G4 Small Form Factor Firmware →
Prodesk 400 G5 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 400 G5 Desktop Mini Firmware →
Prodesk 400 G5 Microtower Firmware by Hp
View all CVEs affecting Prodesk 400 G5 Microtower Firmware →
Prodesk 400 G5 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 400 G5 Small Form Factor Firmware →
Prodesk 400 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 400 G6 Desktop Mini Firmware →
Prodesk 400 G6 Microtower Firmware by Hp
View all CVEs affecting Prodesk 400 G6 Microtower Firmware →
Prodesk 400 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 400 G6 Small Form Factor Firmware →
Prodesk 400 G7 Microtower Firmware by Hp
View all CVEs affecting Prodesk 400 G7 Microtower Firmware →
Prodesk 400 G7 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 400 G7 Small Form Factor Firmware →
Prodesk 405 G4 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 405 G4 Desktop Mini Firmware →
Prodesk 405 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 405 G4 Small Form Factor Firmware →
Prodesk 405 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 405 G6 Desktop Mini Firmware →
Prodesk 405 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 405 G6 Small Form Factor Firmware →
Prodesk 405 G8 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 405 G8 Desktop Mini Firmware →
Prodesk 405 G8 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 405 G8 Small Form Factor Firmware →
Prodesk 480 G4 Microtower Firmware by Hp
View all CVEs affecting Prodesk 480 G4 Microtower Firmware →
Prodesk 480 G5 Microtower Firmware by Hp
View all CVEs affecting Prodesk 480 G5 Microtower Firmware →
Prodesk 480 G6 Microtower Firmware by Hp
View all CVEs affecting Prodesk 480 G6 Microtower Firmware →
Prodesk 600 G2 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G2 Desktop Mini Firmware →
Prodesk 600 G2 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G2 Microtower Firmware →
Prodesk 600 G2 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G2 Small Form Factor Firmware →
Prodesk 600 G3 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G3 Desktop Mini Firmware →
Prodesk 600 G3 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G3 Microtower Firmware →
Prodesk 600 G3 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G3 Small Form Factor Firmware →
Prodesk 600 G4 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Desktop Mini Firmware →
Prodesk 600 G4 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Microtower Firmware →
Prodesk 600 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Small Form Factor Firmware →
Prodesk 600 G5 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Desktop Mini Firmware →
Prodesk 600 G5 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Microtower Firmware →
Prodesk 600 G5 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Small Form Factor Firmware →
Prodesk 600 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G6 Desktop Mini Firmware →
Prodesk 600 G6 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G6 Microtower Firmware →
Prodesk 600 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G6 Small Form Factor Firmware →
Prodesk 680 G2 Microtower Firmware by Hp
View all CVEs affecting Prodesk 680 G2 Microtower Firmware →
Prodesk 680 G3 Microtower Firmware by Hp
View all CVEs affecting Prodesk 680 G3 Microtower Firmware →
Prodesk 680 G4 Microtower Firmware by Hp
View all CVEs affecting Prodesk 680 G4 Microtower Firmware →
Proone 400 G2 20 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 400 G2 20 Inch Non Touch All In One Firmware →
Proone 400 G2 20 Inch Touch All In One Firmware by Hp
View all CVEs affecting Proone 400 G2 20 Inch Touch All In One Firmware →
Proone 400 G3 20 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 400 G3 20 Inch Non Touch All In One Firmware →
Proone 400 G3 20 Inch Touch All In One Firmware by Hp
View all CVEs affecting Proone 400 G3 20 Inch Touch All In One Firmware →
Proone 400 G4 20 Inch Non Touch All In One Business Firmware by Hp
View all CVEs affecting Proone 400 G4 20 Inch Non Touch All In One Business Firmware →
Proone 400 G4 23.8 Inch Non Touch All In One Business Firmware by Hp
View all CVEs affecting Proone 400 G4 23.8 Inch Non Touch All In One Business Firmware →
Proone 400 G5 20 Inch All In One Business Firmware by Hp
View all CVEs affecting Proone 400 G5 20 Inch All In One Business Firmware →
Proone 400 G5 23.8 Inch All In One Business Firmware by Hp
View all CVEs affecting Proone 400 G5 23.8 Inch All In One Business Firmware →
Proone 400 G6 20 All In One Firmware by Hp
View all CVEs affecting Proone 400 G6 20 All In One Firmware →
Proone 400 G6 24 All In One Firmware by Hp
View all CVEs affecting Proone 400 G6 24 All In One Firmware →
Proone 440 23.8 Inch G9 All In One Firmware by Hp
View all CVEs affecting Proone 440 23.8 Inch G9 All In One Firmware →
Proone 440 G4 23.8 Inch Non Touch All In One Business Firmware by Hp
View all CVEs affecting Proone 440 G4 23.8 Inch Non Touch All In One Business Firmware →
Proone 440 G5 23.8 In All In One Business Firmware by Hp
View all CVEs affecting Proone 440 G5 23.8 In All In One Business Firmware →
Proone 440 G6 24 All In One Firmware by Hp
View all CVEs affecting Proone 440 G6 24 All In One Firmware →
Proone 480 G3 20 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 480 G3 20 Inch Non Touch All In One Firmware →
Proone 600 G2 21.5 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 600 G2 21.5 Inch Non Touch All In One Firmware →
Proone 600 G2 21.5 Inch Touch All In One Firmware by Hp
View all CVEs affecting Proone 600 G2 21.5 Inch Touch All In One Firmware →
Proone 600 G3 21.5 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 600 G3 21.5 Inch Non Touch All In One Firmware →
Proone 600 G4 21.5 Inch Touch All In One Business Firmware by Hp
View all CVEs affecting Proone 600 G4 21.5 Inch Touch All In One Business Firmware →
Proone 600 G5 21.5 In All In One Business Firmware by Hp
View all CVEs affecting Proone 600 G5 21.5 In All In One Business Firmware →
Proone 600 G6 22 All In One Firmware by Hp
View all CVEs affecting Proone 600 G6 22 All In One Firmware →
Z1 Entry Tower G5 Workstation Firmware by Hp
View all CVEs affecting Z1 Entry Tower G5 Workstation Firmware →
Z1 Entry Tower G6 Workstation Firmware by Hp
View all CVEs affecting Z1 Entry Tower G6 Workstation Firmware →
Z2 Small Form Factor G4 Workstation Firmware by Hp
View all CVEs affecting Z2 Small Form Factor G4 Workstation Firmware →
Z2 Small Form Factor G5 Workstation Firmware by Hp
View all CVEs affecting Z2 Small Form Factor G5 Workstation Firmware →
Z2 Small Form Factor G8 Workstation Firmware by Hp
View all CVEs affecting Z2 Small Form Factor G8 Workstation Firmware →
Zhan 66 Pro G3 22 All In One Firmware by Hp
View all CVEs affecting Zhan 66 Pro G3 22 All In One Firmware →
⚠️ Risk & Real-World Impact
Worst Case
Complete system compromise with persistent malware in firmware, allowing attackers to maintain control even after OS reinstallation, steal encryption keys and credentials, and disable security controls.
Likely Case
Local privilege escalation allowing attackers to gain administrative access, install persistent malware, or access sensitive system information.
If Mitigated
Limited impact with proper patch management and security controls, potentially only affecting isolated systems with no network access.
🎯 Exploit Status
BIOS exploitation typically requires local access and specialized knowledge. HP describes these as 'potential vulnerabilities' suggesting no confirmed exploitation in the wild.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: Updated BIOS versions from HP
Vendor Advisory: https://support.hp.com/us-en/document/ish_6664419-6664458-16/hpsbhf03806
Restart Required: Yes
Instructions:
1. Visit HP Support website. 2. Enter your HP PC model. 3. Download latest BIOS update. 4. Run BIOS update utility. 5. Restart system as prompted. 6. Verify BIOS version updated.
🔧 Temporary Workarounds
Physical Security Controls
allRestrict physical access to vulnerable systems to prevent local exploitation
BIOS Password Protection
allEnable BIOS/UEFI password to prevent unauthorized BIOS modifications
🧯 If You Can't Patch
- Isolate affected systems from critical networks and sensitive data
- Implement strict physical security controls and monitor for unauthorized access
🔍 How to Verify
Check if Vulnerable:
Check current BIOS version in system settings (F10 during boot on HP systems) or using 'wmic bios get smbiosbiosversion' on Windows
Check Version:
Windows: wmic bios get smbiosbiosversion
Linux: sudo dmidecode -s bios-version
Verify Fix Applied:
Verify BIOS version matches or exceeds the patched version listed in HP's advisory
📡 Detection & Monitoring
Log Indicators:
- BIOS/UEFI modification events in system logs
- Unexpected system restarts or firmware update attempts
Network Indicators:
- Unusual outbound connections from system management interfaces
SIEM Query:
EventID=12 OR EventID=13 (System events) AND (Description contains 'BIOS' OR Description contains 'firmware')