CVE-2022-48219

MEDIUM
Published Feb 14, 2024 Modified Jan 9, 2026 CWE-693

Description

Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.

Is your site exposed to CVE-2022-48219?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.4
MEDIUM
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Weakness Type (CWE)

CWE-693 CWE-693

Affected Products

Vendor Product
hp elite_mini_600_g9_firmware
hp elite_mini_600_g9
hp elite_mini_800_g9_firmware
hp elite_mini_800_g9
hp elite_sff_600_g9_firmware
hp elite_sff_600_g9
hp elite_sff_800_g9_firmware
hp elite_sff_800_g9
hp elite_tower_600_g9_firmware
hp elite_tower_600_g9
hp elite_tower_680_g9_firmware
hp elite_tower_680_g9
hp elite_tower_800_g9_firmware
hp elite_tower_800_g9
hp elite_tower_880_g9_firmware
hp elite_tower_880_g9
hp pro_mini_260_g9_firmware
hp pro_mini_260_g9
hp pro_mini_400_g9_firmware
hp pro_mini_400_g9
hp pro_sff_400_g9_firmware
hp pro_sff_400_g9
hp pro_tower_400_g9_firmware
hp pro_tower_400_g9
hp pro_tower_480_g9_firmware
hp pro_tower_480_g9
hp z1_g8_tower_firmware
hp z1_g8_tower
hp z1_g9_tower_firmware
hp z1_g9_tower
hp elitedesk_800_g8_desktop_mini_firmware
hp elitedesk_800_g8_desktop_mini
hp elitedesk_800_g8_small_form_factor_firmware
hp elitedesk_800_g8_small_form_factor
hp elitedesk_800_g8_tower_firmware
hp elitedesk_800_g8_tower
hp elitedesk_880_g8_tower_firmware
hp elitedesk_880_g8_tower
hp eliteone_800_g8_24_all-in-one_firmware
hp eliteone_800_g8_24_all-in-one
hp eliteone_800_g8_27_all-in-one_firmware
hp eliteone_800_g8_27_all-in-one
hp mini_conferencing_pc_firmware
hp mini_conferencing_pc_with_zoom_rooms
hp z2_mini_g9_firmware
hp z2_mini_g9
hp z2_small_form_factor_g8_firmware
hp z2_small_form_factor_g8
hp z2_small_form_factor_g9_firmware
hp z2_small_form_factor_g9
hp z2_tower_g8_firmware
hp z2_tower_g8
hp z2_tower_g9_firmware
hp z2_tower_g9

References

Frequently Asked Questions

What is CVE-2022-48219? +
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities. It has a CVSS v3.1 base score of 6.4 (MEDIUM).
How severe is CVE-2022-48219? +
CVE-2022-48219 has a CVSS v3.1 score of 6.4 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2022-48219? +
CVE-2022-48219 affects products from hp, specifically: elite_mini_600_g9, elite_mini_600_g9_firmware, elite_mini_800_g9, elite_mini_800_g9_firmware, elite_sff_600_g9, elite_sff_600_g9_firmware, elite_sff_800_g9, elite_sff_800_g9_firmware, elite_tower_600_g9, elite_tower_600_g9_firmware, elite_tower_680_g9, elite_tower_680_g9_firmware, elite_tower_800_g9, elite_tower_800_g9_firmware, elite_tower_880_g9, elite_tower_880_g9_firmware, elitedesk_800_g8_desktop_mini, elitedesk_800_g8_desktop_mini_firmware, elitedesk_800_g8_small_form_factor, elitedesk_800_g8_small_form_factor_firmware, elitedesk_800_g8_tower, elitedesk_800_g8_tower_firmware, elitedesk_880_g8_tower, elitedesk_880_g8_tower_firmware, eliteone_800_g8_24_all-in-one, eliteone_800_g8_24_all-in-one_firmware, eliteone_800_g8_27_all-in-one, eliteone_800_g8_27_all-in-one_firmware, mini_conferencing_pc_firmware, mini_conferencing_pc_with_zoom_rooms, pro_mini_260_g9, pro_mini_260_g9_firmware, pro_mini_400_g9, pro_mini_400_g9_firmware, pro_sff_400_g9, pro_sff_400_g9_firmware, pro_tower_400_g9, pro_tower_400_g9_firmware, pro_tower_480_g9, pro_tower_480_g9_firmware, z1_g8_tower, z1_g8_tower_firmware, z1_g9_tower, z1_g9_tower_firmware, z2_mini_g9, z2_mini_g9_firmware, z2_small_form_factor_g8, z2_small_form_factor_g8_firmware, z2_small_form_factor_g9, z2_small_form_factor_g9_firmware, z2_tower_g8, z2_tower_g8_firmware, z2_tower_g9, z2_tower_g9_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2022-48219? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2022-48219 — free, no signup required.