CVE-2022-4020
Estado: ModificadaAlta (8.2)—
Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 8.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.25%
- Percentil entre todas las CVEs puntuadas: 14
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (5)
CWE
- CWE-276
- CWE-276
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-4020",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-4020",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-04-14T18:15:55.381686Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@eset.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 6,
"exploitabilityScore": 1.5
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.2,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1.5
}
]
},
"affected": [
{
"source": "security@eset.com",
"affectedData": [
{
"vendor": "Acer",
"modules": [
"BIOS/firmware"
],
"product": "Aspire A315-22",
"versions": [
{
"status": "affected",
"version": "1.04",
"lessThan": "1.11",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Acer",
"modules": [
"BIOS/firmware"
],
"product": "Aspire A115-21",
"versions": [
{
"status": "affected",
"version": "1.04",
"lessThan": "1.11",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Acer",
"modules": [
"BIOS/firmware"
],
"product": "Aspire A315-22G",
"versions": [
{
"status": "affected",
"version": "1.04",
"lessThan": "1.11",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Acer",
"modules": [
"BIOS/firmware"
],
"product": "Extensa EX215-21",
"versions": [
{
"status": "affected",
"version": "1.04",
"lessThan": "1.11",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Acer",
"modules": [
"BIOS/firmware"
],
"product": "Extensa EX215-21G",
"versions": [
{
"status": "affected",
"version": "1.04",
"lessThan": "1.11",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2022-11-28T13:15:10.180",
"references": [
{
"url": "https://community.acer.com/en/kb/articles/15520-security-vulnerability-regarding-vulnerability-that-may-allow-changes-to-secure-boot-settings",
"tags": [
"Vendor Advisory"
],
"source": "security@eset.com"
},
{
"url": "https://community.acer.com/en/kb/articles/15520-security-vulnerability-regarding-vulnerability-that-may-allow-changes-to-secure-boot-settings",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@eset.com",
"description": [
{
"lang": "en",
"value": "CWE-276"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-276"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.\n\n\n"
},
{
"lang": "es",
"value": "Una vulnerabilidad en el controlador HQSwSmiDxe DXE en algunos dispositivos portátiles Acer de consumo puede permitir que un atacante con privilegios elevados modifique la configuración de arranque seguro UEFI modificando una variable NVRAM."
}
],
"lastModified": "2026-06-17T05:19:46.683",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:acer:aspire_a315-22g_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF67F568-6A74-4789-B59A-FFE5D03EF0E6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:acer:aspire_a315-22g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A638EBAC-1449-4FE2-BBF9-59517E4D4671"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:acer:aspire_a115-21_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BEBF1F1-34CA-4449-A593-FA0D9C4B3BF2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:acer:aspire_a115-21:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CE7938F2-00F7-470E-B442-F276D175A4FA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:acer:aspire_a315-22_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FB4C05A5-A52F-4115-B0EB-D445E0EA48AF"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:acer:aspire_a315-22:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1C4616CD-F646-4E62-964E-773A5FDA0507"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:acer:extensa_ex215-21_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28620492-E1FD-4A25-9329-F9987FD75723"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:acer:extensa_ex215-21:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A4B5C395-7349-407C-BD81-9D6D2927F8D5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:acer:extensa_ex215-21g_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0557639F-127A-42FE-B5CF-08F3E0A5A296"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:acer:extensa_ex215-21g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E6CD41DC-094E-4765-A234-12CEED5C586C"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@eset.com"
}