CVE-2022-48220
MEDIUMDescription
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.
Is your site exposed to CVE-2022-48220?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| hp | elite_mini_600_g9_firmware |
| hp | elite_mini_600_g9 |
| hp | elite_mini_800_g9_firmware |
| hp | elite_mini_800_g9 |
| hp | elite_sff_600_g9_firmware |
| hp | elite_sff_600_g9 |
| hp | elite_sff_800_g9_firmware |
| hp | elite_sff_800_g9 |
| hp | elite_tower_600_g9_firmware |
| hp | elite_tower_600_g9 |
| hp | elite_tower_680_g9_firmware |
| hp | elite_tower_680_g9 |
| hp | elite_tower_800_g9_firmware |
| hp | elite_tower_800_g9 |
| hp | elite_tower_880_g9_firmware |
| hp | elite_tower_880_g9 |
| hp | elitedesk_800_g8_desktop_mini_firmware |
| hp | elitedesk_800_g8_desktop_mini |
| hp | elitedesk_800_g8_small_form_factor_firmware |
| hp | elitedesk_800_g8_small_form_factor |
| hp | elitedesk_800_g8_tower_firmware |
| hp | elitedesk_800_g8_tower |
| hp | elitedesk_880_g8_tower_firmware |
| hp | elitedesk_880_g8_tower |
| hp | eliteone_800_g8_24_all-in-one_firmware |
| hp | eliteone_800_g8_24_all-in-one |
| hp | eliteone_800_g8_27_all-in-one_firmware |
| hp | eliteone_800_g8_27_all-in-one |
| hp | mini_conferencing_pc_firmware |
| hp | mini_conferencing_pc_with_zoom_rooms |
| hp | pro_mini_260_g9_firmware |
| hp | pro_mini_260_g9 |
| hp | pro_mini_400_g9_firmware |
| hp | pro_mini_400_g9 |
| hp | pro_sff_400_g9_firmware |
| hp | pro_sff_400_g9 |
| hp | pro_tower_400_g9_firmware |
| hp | pro_tower_400_g9 |
| hp | pro_tower_480_g9_firmware |
| hp | pro_tower_480_g9 |
| hp | z1_g8_tower_firmware |
| hp | z1_g8_tower |
| hp | z1_g9_tower_firmware |
| hp | z1_g9_tower |
| hp | z2_mini_g9_firmware |
| hp | z2_mini_g9 |
| hp | z2_small_form_factor_g8_firmware |
| hp | z2_small_form_factor_g8 |
| hp | z2_small_form_factor_g9_firmware |
| hp | z2_small_form_factor_g9 |
| hp | z2_tower_g8_firmware |
| hp | z2_tower_g8 |
| hp | z2_tower_g9_firmware |
| hp | z2_tower_g9 |
References
Frequently Asked Questions
What is CVE-2022-48220? +
How severe is CVE-2022-48220? +
What products are affected by CVE-2022-48220? +
How do I check if I'm vulnerable to CVE-2022-48220? +
Related Vulnerabilities
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy …
A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.
Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret Sharing (VSS) scheme. In versions 0.8.0b2 …
Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.
Timing difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2.4 and 8.3.1 allows unauthenticated attackers …
Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially …