CVE-2022-31644
📋 TL;DR
This CVE describes BIOS vulnerabilities in certain HP PC products that could allow attackers to execute arbitrary code, escalate privileges, cause denial of service, or disclose sensitive information. The vulnerability affects HP PC users with specific BIOS versions and requires physical or administrative access to exploit. This is an incorrect authorization vulnerability (CWE-863) in the system BIOS.
💻 Affected Systems
- HP PC products with specific BIOS versions
📦 What is this software?
Dragonfly Folio G3 2 In 1 Firmware by Hp
View all CVEs affecting Dragonfly Folio G3 2 In 1 Firmware →
Elite X360 1040 G9 2 In 1 Firmware by Hp
View all CVEs affecting Elite X360 1040 G9 2 In 1 Firmware →
Elitedesk 705 G4 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 705 G4 Desktop Mini Firmware →
Elitedesk 705 G4 Microtower Firmware by Hp
View all CVEs affecting Elitedesk 705 G4 Microtower Firmware →
Elitedesk 705 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 705 G4 Small Form Factor Firmware →
Elitedesk 705 G4 Workstation Firmware by Hp
View all CVEs affecting Elitedesk 705 G4 Workstation Firmware →
Elitedesk 705 G5 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 705 G5 Desktop Mini Firmware →
Elitedesk 705 G5 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 705 G5 Small Form Factor Firmware →
Elitedesk 800 35w G2 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 35w G2 Desktop Mini Firmware →
Elitedesk 800 35w G3 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 35w G3 Desktop Mini Firmware →
Elitedesk 800 35w G4 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 35w G4 Desktop Mini Firmware →
Elitedesk 800 65w G2 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 65w G2 Desktop Mini Firmware →
Elitedesk 800 65w G3 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 65w G3 Desktop Mini Firmware →
Elitedesk 800 65w G4 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 65w G4 Desktop Mini Firmware →
Elitedesk 800 95w G4 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 95w G4 Desktop Mini Firmware →
Elitedesk 800 G2 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G2 Small Form Factor Firmware →
Elitedesk 800 G3 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G3 Small Form Factor Firmware →
Elitedesk 800 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G4 Small Form Factor Firmware →
Elitedesk 800 G4 Workstation Firmware by Hp
View all CVEs affecting Elitedesk 800 G4 Workstation Firmware →
Elitedesk 800 G5 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 G5 Desktop Mini Firmware →
Elitedesk 800 G5 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G5 Small Form Factor Firmware →
Elitedesk 800 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 G6 Desktop Mini Firmware →
Elitedesk 800 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G6 Small Form Factor Firmware →
Elitedesk 800 G8 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 G8 Desktop Mini Firmware →
Elitedesk 800 G8 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G8 Small Form Factor Firmware →
Elitedesk 805 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 805 G6 Desktop Mini Firmware →
Elitedesk 805 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 805 G6 Small Form Factor Firmware →
Elitedesk 805 G8 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 805 G8 Desktop Mini Firmware →
Elitedesk 805 G8 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 805 G8 Small Form Factor Firmware →
Eliteone 1000 G1 23.8 In All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G1 23.8 In All In One Business Firmware →
Eliteone 1000 G1 23.8 In Touch All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G1 23.8 In Touch All In One Business Firmware →
Eliteone 1000 G1 27 In 4k Uhd All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G1 27 In 4k Uhd All In One Business Firmware →
Eliteone 1000 G1 34 In Curved All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G1 34 In Curved All In One Business Firmware →
Eliteone 1000 G2 23.8 In All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 23.8 In All In One Business Firmware →
Eliteone 1000 G2 23.8 In Touch All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 23.8 In Touch All In One Business Firmware →
Eliteone 1000 G2 27 In 4k Uhd All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 27 In 4k Uhd All In One Business Firmware →
Eliteone 1000 G2 34 In Curved All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 34 In Curved All In One Business Firmware →
Eliteone 800 G2 23 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G2 23 Inch Non Touch All In One Firmware →
Eliteone 800 G2 23 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G2 23 Inch Non Touch All In One Firmware →
Eliteone 800 G2 23 Inch Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G2 23 Inch Touch All In One Firmware →
Eliteone 800 G2 23 Inch Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G2 23 Inch Touch All In One Firmware →
Eliteone 800 G3 23.8 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Inch Non Touch All In One Firmware →
Eliteone 800 G3 23.8 Inch Non Touch Gpu All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Inch Non Touch Gpu All In One Firmware →
Eliteone 800 G3 23.8 Inch Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Inch Touch All In One Firmware →
Eliteone 800 G3 23.8 Inch Touch Gpu All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Inch Touch Gpu All In One Firmware →
Eliteone 800 G3 23.8 Non Touch All In One Business Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Non Touch All In One Business Firmware →
Eliteone 800 G4 23.8 In All In One Business Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 In All In One Business Firmware →
Eliteone 800 G4 23.8 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Non Touch All In One Firmware →
Eliteone 800 G4 23.8 Inch Non Touch Gpu All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Non Touch Gpu All In One Firmware →
Eliteone 800 G4 23.8 Inch Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Touch All In One Firmware →
Eliteone 800 G4 23.8 Inch Touch Gpu All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Touch Gpu All In One Firmware →
Eliteone 800 G5 23.8 In All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G5 23.8 In All In One Firmware →
Eliteone 800 G5 23.8 Inch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G5 23.8 Inch All In One Firmware →
Eliteone 800 G6 24 All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G6 24 All In One Firmware →
Eliteone 800 G6 27 All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G6 27 All In One Firmware →
Eliteone 800 G8 24 All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G8 24 All In One Firmware →
Eliteone 800 G8 27 All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G8 27 All In One Firmware →
Eliteone 840 23.8 Inch G9 All In One Firmware by Hp
View all CVEs affecting Eliteone 840 23.8 Inch G9 All In One Firmware →
Engage Flex Mini Retail System Firmware by Hp
View all CVEs affecting Engage Flex Mini Retail System Firmware →
Engage Flex Pro C Retail System Firmware by Hp
View all CVEs affecting Engage Flex Pro C Retail System Firmware →
Engage Flex Pro Retail System Firmware by Hp
View all CVEs affecting Engage Flex Pro Retail System Firmware →
Engage Go 10 Mobile System Firmware by Hp
View all CVEs affecting Engage Go 10 Mobile System Firmware →
Engage One Pro Aio System Firmware by Hp
View all CVEs affecting Engage One Pro Aio System Firmware →
Prodesk 400 G3 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 400 G3 Desktop Mini Firmware →
Prodesk 400 G4 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 400 G4 Desktop Mini Firmware →
Prodesk 400 G4 Microtower Firmware by Hp
View all CVEs affecting Prodesk 400 G4 Microtower Firmware →
Prodesk 400 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 400 G4 Small Form Factor Firmware →
Prodesk 400 G5 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 400 G5 Desktop Mini Firmware →
Prodesk 400 G5 Microtower Firmware by Hp
View all CVEs affecting Prodesk 400 G5 Microtower Firmware →
Prodesk 400 G5 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 400 G5 Small Form Factor Firmware →
Prodesk 400 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 400 G6 Desktop Mini Firmware →
Prodesk 400 G6 Microtower Firmware by Hp
View all CVEs affecting Prodesk 400 G6 Microtower Firmware →
Prodesk 400 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 400 G6 Small Form Factor Firmware →
Prodesk 400 G7 Microtower Firmware by Hp
View all CVEs affecting Prodesk 400 G7 Microtower Firmware →
Prodesk 400 G7 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 400 G7 Small Form Factor Firmware →
Prodesk 405 G4 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 405 G4 Desktop Mini Firmware →
Prodesk 405 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 405 G4 Small Form Factor Firmware →
Prodesk 405 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 405 G6 Desktop Mini Firmware →
Prodesk 405 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 405 G6 Small Form Factor Firmware →
Prodesk 405 G8 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 405 G8 Desktop Mini Firmware →
Prodesk 405 G8 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 405 G8 Small Form Factor Firmware →
Prodesk 480 G4 Microtower Firmware by Hp
View all CVEs affecting Prodesk 480 G4 Microtower Firmware →
Prodesk 480 G5 Microtower Firmware by Hp
View all CVEs affecting Prodesk 480 G5 Microtower Firmware →
Prodesk 480 G6 Microtower Firmware by Hp
View all CVEs affecting Prodesk 480 G6 Microtower Firmware →
Prodesk 600 G2 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G2 Desktop Mini Firmware →
Prodesk 600 G2 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G2 Microtower Firmware →
Prodesk 600 G2 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G2 Small Form Factor Firmware →
Prodesk 600 G3 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G3 Desktop Mini Firmware →
Prodesk 600 G3 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G3 Microtower Firmware →
Prodesk 600 G3 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G3 Small Form Factor Firmware →
Prodesk 600 G4 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Desktop Mini Firmware →
Prodesk 600 G4 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Microtower Firmware →
Prodesk 600 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Small Form Factor Firmware →
Prodesk 600 G5 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Desktop Mini Firmware →
Prodesk 600 G5 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Microtower Firmware →
Prodesk 600 G5 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Small Form Factor Firmware →
Prodesk 600 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G6 Desktop Mini Firmware →
Prodesk 600 G6 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G6 Microtower Firmware →
Prodesk 600 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G6 Small Form Factor Firmware →
Prodesk 680 G2 Microtower Firmware by Hp
View all CVEs affecting Prodesk 680 G2 Microtower Firmware →
Prodesk 680 G3 Microtower Firmware by Hp
View all CVEs affecting Prodesk 680 G3 Microtower Firmware →
Prodesk 680 G4 Microtower Firmware by Hp
View all CVEs affecting Prodesk 680 G4 Microtower Firmware →
Proone 400 G2 20 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 400 G2 20 Inch Non Touch All In One Firmware →
Proone 400 G2 20 Inch Touch All In One Firmware by Hp
View all CVEs affecting Proone 400 G2 20 Inch Touch All In One Firmware →
Proone 400 G3 20 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 400 G3 20 Inch Non Touch All In One Firmware →
Proone 400 G3 20 Inch Touch All In One Firmware by Hp
View all CVEs affecting Proone 400 G3 20 Inch Touch All In One Firmware →
Proone 400 G4 20 Inch Non Touch All In One Business Firmware by Hp
View all CVEs affecting Proone 400 G4 20 Inch Non Touch All In One Business Firmware →
Proone 400 G4 23.8 Inch Non Touch All In One Business Firmware by Hp
View all CVEs affecting Proone 400 G4 23.8 Inch Non Touch All In One Business Firmware →
Proone 400 G5 20 Inch All In One Business Firmware by Hp
View all CVEs affecting Proone 400 G5 20 Inch All In One Business Firmware →
Proone 400 G5 23.8 Inch All In One Business Firmware by Hp
View all CVEs affecting Proone 400 G5 23.8 Inch All In One Business Firmware →
Proone 400 G6 20 All In One Firmware by Hp
View all CVEs affecting Proone 400 G6 20 All In One Firmware →
Proone 400 G6 24 All In One Firmware by Hp
View all CVEs affecting Proone 400 G6 24 All In One Firmware →
Proone 440 23.8 Inch G9 All In One Firmware by Hp
View all CVEs affecting Proone 440 23.8 Inch G9 All In One Firmware →
Proone 440 G4 23.8 Inch Non Touch All In One Business Firmware by Hp
View all CVEs affecting Proone 440 G4 23.8 Inch Non Touch All In One Business Firmware →
Proone 440 G5 23.8 In All In One Business Firmware by Hp
View all CVEs affecting Proone 440 G5 23.8 In All In One Business Firmware →
Proone 440 G6 24 All In One Firmware by Hp
View all CVEs affecting Proone 440 G6 24 All In One Firmware →
Proone 480 G3 20 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 480 G3 20 Inch Non Touch All In One Firmware →
Proone 600 G2 21.5 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 600 G2 21.5 Inch Non Touch All In One Firmware →
Proone 600 G2 21.5 Inch Touch All In One Firmware by Hp
View all CVEs affecting Proone 600 G2 21.5 Inch Touch All In One Firmware →
Proone 600 G3 21.5 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 600 G3 21.5 Inch Non Touch All In One Firmware →
Proone 600 G4 21.5 Inch Touch All In One Business Firmware by Hp
View all CVEs affecting Proone 600 G4 21.5 Inch Touch All In One Business Firmware →
Proone 600 G5 21.5 In All In One Business Firmware by Hp
View all CVEs affecting Proone 600 G5 21.5 In All In One Business Firmware →
Proone 600 G6 22 All In One Firmware by Hp
View all CVEs affecting Proone 600 G6 22 All In One Firmware →
Z1 Entry Tower G5 Workstation Firmware by Hp
View all CVEs affecting Z1 Entry Tower G5 Workstation Firmware →
Z1 Entry Tower G6 Workstation Firmware by Hp
View all CVEs affecting Z1 Entry Tower G6 Workstation Firmware →
Z2 Small Form Factor G4 Workstation Firmware by Hp
View all CVEs affecting Z2 Small Form Factor G4 Workstation Firmware →
Z2 Small Form Factor G5 Workstation Firmware by Hp
View all CVEs affecting Z2 Small Form Factor G5 Workstation Firmware →
Z2 Small Form Factor G8 Workstation Firmware by Hp
View all CVEs affecting Z2 Small Form Factor G8 Workstation Firmware →
Zhan 66 Pro G3 22 All In One Firmware by Hp
View all CVEs affecting Zhan 66 Pro G3 22 All In One Firmware →
⚠️ Risk & Real-World Impact
Worst Case
An attacker with physical or administrative access could gain complete control of the system, bypass all security controls, install persistent malware in firmware, and access sensitive data including encryption keys.
Likely Case
Malicious insiders or attackers with physical access could escalate privileges, bypass security controls, and potentially maintain persistence through firmware-level compromise.
If Mitigated
With proper physical security controls and BIOS password protection, the attack surface is significantly reduced, though the vulnerability remains present in the firmware.
🎯 Exploit Status
Exploitation requires physical access or administrative privileges. The vulnerability involves incorrect authorization checks in BIOS functions that could be manipulated by an attacker with access to BIOS/UEFI settings or firmware update mechanisms.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: BIOS updates provided by HP for specific models
Vendor Advisory: https://support.hp.com/us-en/document/ish_6664419-6664458-16/hpsbhf03806
Restart Required: Yes
Instructions:
1. Identify your HP PC model and current BIOS version. 2. Visit HP Support website and search for BIOS updates for your specific model. 3. Download the latest BIOS update from HP's official site. 4. Follow HP's instructions to update the BIOS (typically involves running an executable in Windows or using a USB flash drive). 5. Restart the system as required by the update process.
🔧 Temporary Workarounds
Enable BIOS/UEFI Password
allSet a strong BIOS/UEFI password to prevent unauthorized access to BIOS settings and firmware update functions.
Physical Security Controls
allImplement physical security measures to prevent unauthorized physical access to systems, including locked server rooms, cable locks for laptops, and access controls.
🧯 If You Can't Patch
- Implement strict physical security controls and limit physical access to affected systems
- Enable BIOS/UEFI passwords and secure boot features to reduce attack surface
🔍 How to Verify
Check if Vulnerable:
Check your HP PC model and BIOS version against HP's security bulletin. In Windows, you can check BIOS version via System Information (msinfo32) or Command Prompt (wmic bios get smbiosbiosversion).
Check Version:
wmic bios get smbiosbiosversion (Windows) or dmidecode -s bios-version (Linux)
Verify Fix Applied:
After BIOS update, verify the new BIOS version matches the patched version listed in HP's security advisory. Check that the version has increased from the vulnerable version.
📡 Detection & Monitoring
Log Indicators:
- Unexpected BIOS/UEFI configuration changes
- Failed BIOS update attempts
- Unauthorized physical access logs
Network Indicators:
- BIOS updates typically do not generate network traffic unless using network-based update mechanisms
SIEM Query:
Search for events related to BIOS/UEFI configuration changes, firmware updates, or physical security breaches on affected HP systems.