CVE-2022-31646
📋 TL;DR
This CVE describes BIOS vulnerabilities in certain HP PC products that could allow attackers to execute arbitrary code, escalate privileges, cause denial of service, or disclose sensitive information. The vulnerability affects HP PC users with specific BIOS versions. Attackers would need physical or administrative access to exploit these flaws.
💻 Affected Systems
- HP PC products (specific models listed in HP advisory)
📦 What is this software?
Dragonfly Folio G3 2 In 1 Firmware by Hp
View all CVEs affecting Dragonfly Folio G3 2 In 1 Firmware →
Elite X360 1040 G9 2 In 1 Firmware by Hp
View all CVEs affecting Elite X360 1040 G9 2 In 1 Firmware →
Elitedesk 705 G4 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 705 G4 Desktop Mini Firmware →
Elitedesk 705 G4 Microtower Firmware by Hp
View all CVEs affecting Elitedesk 705 G4 Microtower Firmware →
Elitedesk 705 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 705 G4 Small Form Factor Firmware →
Elitedesk 705 G4 Workstation Firmware by Hp
View all CVEs affecting Elitedesk 705 G4 Workstation Firmware →
Elitedesk 705 G5 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 705 G5 Desktop Mini Firmware →
Elitedesk 705 G5 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 705 G5 Small Form Factor Firmware →
Elitedesk 800 35w G2 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 35w G2 Desktop Mini Firmware →
Elitedesk 800 35w G3 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 35w G3 Desktop Mini Firmware →
Elitedesk 800 35w G4 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 35w G4 Desktop Mini Firmware →
Elitedesk 800 65w G2 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 65w G2 Desktop Mini Firmware →
Elitedesk 800 65w G3 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 65w G3 Desktop Mini Firmware →
Elitedesk 800 65w G4 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 65w G4 Desktop Mini Firmware →
Elitedesk 800 95w G4 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 95w G4 Desktop Mini Firmware →
Elitedesk 800 G2 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G2 Small Form Factor Firmware →
Elitedesk 800 G3 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G3 Small Form Factor Firmware →
Elitedesk 800 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G4 Small Form Factor Firmware →
Elitedesk 800 G4 Workstation Firmware by Hp
View all CVEs affecting Elitedesk 800 G4 Workstation Firmware →
Elitedesk 800 G5 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 G5 Desktop Mini Firmware →
Elitedesk 800 G5 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G5 Small Form Factor Firmware →
Elitedesk 800 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 G6 Desktop Mini Firmware →
Elitedesk 800 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G6 Small Form Factor Firmware →
Elitedesk 800 G8 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 800 G8 Desktop Mini Firmware →
Elitedesk 800 G8 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 800 G8 Small Form Factor Firmware →
Elitedesk 805 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 805 G6 Desktop Mini Firmware →
Elitedesk 805 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 805 G6 Small Form Factor Firmware →
Elitedesk 805 G8 Desktop Mini Firmware by Hp
View all CVEs affecting Elitedesk 805 G8 Desktop Mini Firmware →
Elitedesk 805 G8 Small Form Factor Firmware by Hp
View all CVEs affecting Elitedesk 805 G8 Small Form Factor Firmware →
Eliteone 1000 G1 23.8 In All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G1 23.8 In All In One Business Firmware →
Eliteone 1000 G1 23.8 In Touch All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G1 23.8 In Touch All In One Business Firmware →
Eliteone 1000 G1 27 In 4k Uhd All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G1 27 In 4k Uhd All In One Business Firmware →
Eliteone 1000 G1 34 In Curved All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G1 34 In Curved All In One Business Firmware →
Eliteone 1000 G2 23.8 In All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 23.8 In All In One Business Firmware →
Eliteone 1000 G2 23.8 In Touch All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 23.8 In Touch All In One Business Firmware →
Eliteone 1000 G2 27 In 4k Uhd All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 27 In 4k Uhd All In One Business Firmware →
Eliteone 1000 G2 34 In Curved All In One Business Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 34 In Curved All In One Business Firmware →
Eliteone 800 G2 23 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G2 23 Inch Non Touch All In One Firmware →
Eliteone 800 G2 23 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G2 23 Inch Non Touch All In One Firmware →
Eliteone 800 G2 23 Inch Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G2 23 Inch Touch All In One Firmware →
Eliteone 800 G2 23 Inch Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G2 23 Inch Touch All In One Firmware →
Eliteone 800 G3 23.8 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Inch Non Touch All In One Firmware →
Eliteone 800 G3 23.8 Inch Non Touch Gpu All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Inch Non Touch Gpu All In One Firmware →
Eliteone 800 G3 23.8 Inch Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Inch Touch All In One Firmware →
Eliteone 800 G3 23.8 Inch Touch Gpu All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Inch Touch Gpu All In One Firmware →
Eliteone 800 G3 23.8 Non Touch All In One Business Firmware by Hp
View all CVEs affecting Eliteone 800 G3 23.8 Non Touch All In One Business Firmware →
Eliteone 800 G4 23.8 In All In One Business Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 In All In One Business Firmware →
Eliteone 800 G4 23.8 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Non Touch All In One Firmware →
Eliteone 800 G4 23.8 Inch Non Touch Gpu All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Non Touch Gpu All In One Firmware →
Eliteone 800 G4 23.8 Inch Touch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Touch All In One Firmware →
Eliteone 800 G4 23.8 Inch Touch Gpu All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Touch Gpu All In One Firmware →
Eliteone 800 G5 23.8 In All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G5 23.8 In All In One Firmware →
Eliteone 800 G5 23.8 Inch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G5 23.8 Inch All In One Firmware →
Eliteone 800 G6 24 All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G6 24 All In One Firmware →
Eliteone 800 G6 27 All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G6 27 All In One Firmware →
Eliteone 800 G8 24 All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G8 24 All In One Firmware →
Eliteone 800 G8 27 All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G8 27 All In One Firmware →
Eliteone 840 23.8 Inch G9 All In One Firmware by Hp
View all CVEs affecting Eliteone 840 23.8 Inch G9 All In One Firmware →
Engage Flex Mini Retail System Firmware by Hp
View all CVEs affecting Engage Flex Mini Retail System Firmware →
Engage Flex Pro C Retail System Firmware by Hp
View all CVEs affecting Engage Flex Pro C Retail System Firmware →
Engage Flex Pro Retail System Firmware by Hp
View all CVEs affecting Engage Flex Pro Retail System Firmware →
Engage Go 10 Mobile System Firmware by Hp
View all CVEs affecting Engage Go 10 Mobile System Firmware →
Engage One Pro Aio System Firmware by Hp
View all CVEs affecting Engage One Pro Aio System Firmware →
Prodesk 400 G3 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 400 G3 Desktop Mini Firmware →
Prodesk 400 G4 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 400 G4 Desktop Mini Firmware →
Prodesk 400 G4 Microtower Firmware by Hp
View all CVEs affecting Prodesk 400 G4 Microtower Firmware →
Prodesk 400 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 400 G4 Small Form Factor Firmware →
Prodesk 400 G5 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 400 G5 Desktop Mini Firmware →
Prodesk 400 G5 Microtower Firmware by Hp
View all CVEs affecting Prodesk 400 G5 Microtower Firmware →
Prodesk 400 G5 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 400 G5 Small Form Factor Firmware →
Prodesk 400 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 400 G6 Desktop Mini Firmware →
Prodesk 400 G6 Microtower Firmware by Hp
View all CVEs affecting Prodesk 400 G6 Microtower Firmware →
Prodesk 400 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 400 G6 Small Form Factor Firmware →
Prodesk 400 G7 Microtower Firmware by Hp
View all CVEs affecting Prodesk 400 G7 Microtower Firmware →
Prodesk 400 G7 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 400 G7 Small Form Factor Firmware →
Prodesk 405 G4 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 405 G4 Desktop Mini Firmware →
Prodesk 405 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 405 G4 Small Form Factor Firmware →
Prodesk 405 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 405 G6 Desktop Mini Firmware →
Prodesk 405 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 405 G6 Small Form Factor Firmware →
Prodesk 405 G8 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 405 G8 Desktop Mini Firmware →
Prodesk 405 G8 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 405 G8 Small Form Factor Firmware →
Prodesk 480 G4 Microtower Firmware by Hp
View all CVEs affecting Prodesk 480 G4 Microtower Firmware →
Prodesk 480 G5 Microtower Firmware by Hp
View all CVEs affecting Prodesk 480 G5 Microtower Firmware →
Prodesk 480 G6 Microtower Firmware by Hp
View all CVEs affecting Prodesk 480 G6 Microtower Firmware →
Prodesk 600 G2 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G2 Desktop Mini Firmware →
Prodesk 600 G2 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G2 Microtower Firmware →
Prodesk 600 G2 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G2 Small Form Factor Firmware →
Prodesk 600 G3 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G3 Desktop Mini Firmware →
Prodesk 600 G3 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G3 Microtower Firmware →
Prodesk 600 G3 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G3 Small Form Factor Firmware →
Prodesk 600 G4 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Desktop Mini Firmware →
Prodesk 600 G4 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Microtower Firmware →
Prodesk 600 G4 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Small Form Factor Firmware →
Prodesk 600 G5 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Desktop Mini Firmware →
Prodesk 600 G5 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Microtower Firmware →
Prodesk 600 G5 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Small Form Factor Firmware →
Prodesk 600 G6 Desktop Mini Firmware by Hp
View all CVEs affecting Prodesk 600 G6 Desktop Mini Firmware →
Prodesk 600 G6 Microtower Firmware by Hp
View all CVEs affecting Prodesk 600 G6 Microtower Firmware →
Prodesk 600 G6 Small Form Factor Firmware by Hp
View all CVEs affecting Prodesk 600 G6 Small Form Factor Firmware →
Prodesk 680 G2 Microtower Firmware by Hp
View all CVEs affecting Prodesk 680 G2 Microtower Firmware →
Prodesk 680 G3 Microtower Firmware by Hp
View all CVEs affecting Prodesk 680 G3 Microtower Firmware →
Prodesk 680 G4 Microtower Firmware by Hp
View all CVEs affecting Prodesk 680 G4 Microtower Firmware →
Proone 400 G2 20 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 400 G2 20 Inch Non Touch All In One Firmware →
Proone 400 G2 20 Inch Touch All In One Firmware by Hp
View all CVEs affecting Proone 400 G2 20 Inch Touch All In One Firmware →
Proone 400 G3 20 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 400 G3 20 Inch Non Touch All In One Firmware →
Proone 400 G3 20 Inch Touch All In One Firmware by Hp
View all CVEs affecting Proone 400 G3 20 Inch Touch All In One Firmware →
Proone 400 G4 20 Inch Non Touch All In One Business Firmware by Hp
View all CVEs affecting Proone 400 G4 20 Inch Non Touch All In One Business Firmware →
Proone 400 G4 23.8 Inch Non Touch All In One Business Firmware by Hp
View all CVEs affecting Proone 400 G4 23.8 Inch Non Touch All In One Business Firmware →
Proone 400 G5 20 Inch All In One Business Firmware by Hp
View all CVEs affecting Proone 400 G5 20 Inch All In One Business Firmware →
Proone 400 G5 23.8 Inch All In One Business Firmware by Hp
View all CVEs affecting Proone 400 G5 23.8 Inch All In One Business Firmware →
Proone 400 G6 20 All In One Firmware by Hp
View all CVEs affecting Proone 400 G6 20 All In One Firmware →
Proone 400 G6 24 All In One Firmware by Hp
View all CVEs affecting Proone 400 G6 24 All In One Firmware →
Proone 440 23.8 Inch G9 All In One Firmware by Hp
View all CVEs affecting Proone 440 23.8 Inch G9 All In One Firmware →
Proone 440 G4 23.8 Inch Non Touch All In One Business Firmware by Hp
View all CVEs affecting Proone 440 G4 23.8 Inch Non Touch All In One Business Firmware →
Proone 440 G5 23.8 In All In One Business Firmware by Hp
View all CVEs affecting Proone 440 G5 23.8 In All In One Business Firmware →
Proone 440 G6 24 All In One Firmware by Hp
View all CVEs affecting Proone 440 G6 24 All In One Firmware →
Proone 480 G3 20 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 480 G3 20 Inch Non Touch All In One Firmware →
Proone 600 G2 21.5 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 600 G2 21.5 Inch Non Touch All In One Firmware →
Proone 600 G2 21.5 Inch Touch All In One Firmware by Hp
View all CVEs affecting Proone 600 G2 21.5 Inch Touch All In One Firmware →
Proone 600 G3 21.5 Inch Non Touch All In One Firmware by Hp
View all CVEs affecting Proone 600 G3 21.5 Inch Non Touch All In One Firmware →
Proone 600 G4 21.5 Inch Touch All In One Business Firmware by Hp
View all CVEs affecting Proone 600 G4 21.5 Inch Touch All In One Business Firmware →
Proone 600 G5 21.5 In All In One Business Firmware by Hp
View all CVEs affecting Proone 600 G5 21.5 In All In One Business Firmware →
Proone 600 G6 22 All In One Firmware by Hp
View all CVEs affecting Proone 600 G6 22 All In One Firmware →
Z1 Entry Tower G5 Workstation Firmware by Hp
View all CVEs affecting Z1 Entry Tower G5 Workstation Firmware →
Z1 Entry Tower G6 Workstation Firmware by Hp
View all CVEs affecting Z1 Entry Tower G6 Workstation Firmware →
Z2 Small Form Factor G4 Workstation Firmware by Hp
View all CVEs affecting Z2 Small Form Factor G4 Workstation Firmware →
Z2 Small Form Factor G5 Workstation Firmware by Hp
View all CVEs affecting Z2 Small Form Factor G5 Workstation Firmware →
Z2 Small Form Factor G8 Workstation Firmware by Hp
View all CVEs affecting Z2 Small Form Factor G8 Workstation Firmware →
Zhan 66 Pro G3 22 All In One Firmware by Hp
View all CVEs affecting Zhan 66 Pro G3 22 All In One Firmware →
⚠️ Risk & Real-World Impact
Worst Case
Complete system compromise with persistent malware at firmware level, allowing attackers to bypass operating system security controls and maintain persistence across OS reinstalls.
Likely Case
Local attacker with administrative access could install persistent malware or extract sensitive information from firmware.
If Mitigated
With proper access controls and BIOS password protection, risk is limited to authorized administrators only.
🎯 Exploit Status
Exploitation requires local access and BIOS/UEFI knowledge. No public exploits known at this time.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: BIOS updates specified in HP Security Bulletin HPSBHF03806
Vendor Advisory: https://support.hp.com/us-en/document/ish_6664419-6664458-16/hpsbhf03806
Restart Required: Yes
Instructions:
1. Identify your HP PC model. 2. Visit HP Support website. 3. Download latest BIOS update for your model. 4. Run BIOS update utility. 5. Restart system when prompted.
🔧 Temporary Workarounds
BIOS Password Protection
allSet BIOS administrator password to prevent unauthorized BIOS modifications
Access BIOS/UEFI settings during boot (typically F10 or ESC)
Navigate to Security settings
Set Administrator Password
Physical Security Controls
allRestrict physical access to vulnerable systems
🧯 If You Can't Patch
- Implement strict physical access controls to prevent unauthorized local access
- Enable BIOS password protection and secure boot features
🔍 How to Verify
Check if Vulnerable:
Check BIOS version in system information (Windows: msinfo32, Linux: dmidecode -t bios) and compare against HP advisory
Check Version:
Windows: wmic bios get smbiosbiosversion | Linux: dmidecode -s bios-version
Verify Fix Applied:
Verify BIOS version after update matches patched version in HP advisory
📡 Detection & Monitoring
Log Indicators:
- BIOS/UEFI firmware modification events
- Unauthorized physical access logs
- Failed BIOS password attempts
Network Indicators:
- Not applicable - local exploit only
SIEM Query:
Event ID 12 (System) with BIOS/UEFI firmware changes on Windows systems