---
id: CVE-2022-23928
title: >-
  Potential vulnerabilities have been identified in the system BIOS of certain
  HP PC products which may allow Escalation of Privilege, Arbitrary Code
  Execution, Unauthorized Code Execution, Denial of Service, and Information
  Disclosure.
summary: >-
  Potential vulnerabilities have been identified in the system BIOS of certain
  HP PC products which may allow Escalation of Privilege, Arbitrary Code
  Execution, Unauthorized Code Execution, Denial of Service, and Information
  Disclosure.
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
vendor: hp
product: pc_bios
affected:
  - pc_bios < 02.07.10
patched:
  - pc_bios 02.07.10
published: '2022-03-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:17.367'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-23928'
references:
  - url: 'https://support.hp.com/us-en/document/ish_5817864-5817896-16'
    label: hp-security-alert@hp.com
  - url: 'https://support.hp.com/us-en/document/ish_5817864-5817896-16'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00437
epssPercentile: 0.35954
ingestedAt: '2026-10-08T23:16:47.337Z'
---

## Overview

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

## Affected

- `pc_bios < 02.07.10`

## Remediation

Upgrade past the affected range:

- `pc_bios 02.07.10`
