« Back to list

CVE-2022-23953

Status: ModifiedMedium (5.5)—

Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2022-23953",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "hp-security-alert@hp.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "HP ProBook 440 G8 Notebook PC; HP ProDesk 405 G6 Small Form Factor PC",
          "versions": [
            {
              "status": "affected",
              "version": "before 01.08.11"
            },
            {
              "status": "affected",
              "version": "before 02.07.10 (S05, S15 BIOS)"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-03-02T21:15:08.220",
  "references": [
    {
      "url": "https://support.hp.com/us-en/document/ish_5818692-5818718-16",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "https://support.hp.com/us-en/document/ish_5818692-5818718-16",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service."
    },
    {
      "lang": "es",
      "value": "Se han identificado posibles vulnerabilidades en la BIOS de algunos productos de PC de HP que pueden permitir una denegación de servicio"
    }
  ],
  "lastModified": "2026-06-17T04:31:03.030",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hp:probook_440_g8_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B3ADE40-CC06-499A-8375-407BD7FDDCDF",
              "versionEndExcluding": "01.08.11"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hp:probook_440_g8:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2F93D1E8-C7A7-4B35-9389-AAC3DD0FA978"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hp:prodesk_405_g6_small_form_factor_firmware:*:*:*:*:s05:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9CCD57BC-7EFA-42B9-A44B-EB81955B522E",
              "versionEndExcluding": "02.07.10"
            },
            {
              "criteria": "cpe:2.3:o:hp:prodesk_405_g6_small_form_factor_firmware:*:*:*:*:s15:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90AE1566-5690-42AB-81A2-CA74C73E7192",
              "versionEndExcluding": "02.07.10"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hp:prodesk_405_g6_small_form_factor:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BDF257E9-0F71-4E30-9720-72834A9327C9"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "hp-security-alert@hp.com"
}