CVE-2022-4020: Acer Aspire BIOS vulnerability
Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4020?
CVE-2022-4020 is a vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices.
How does CVE-2022-4020 impact Acer Aspire A315-22g Firmware?
CVE-2022-4020 may allow an attacker with elevated privileges to modify UEFI Secure Boot settings on Acer Aspire A315-22g Firmware.
Is Acer Aspire A315-22g vulnerable to CVE-2022-4020?
No, Acer Aspire A315-22g is not vulnerable to CVE-2022-4020.
How severe is CVE-2022-4020?
CVE-2022-4020 has a severity rating of 8.2 (high).
How can I fix CVE-2022-4020?
Acer has released a security update to address the vulnerability. Please refer to the following link for more information: [link](https://community.acer.com/en/kb/articles/15520-security-vulnerability-regarding-vulnerability-that-may-allow-changes-to-secure-boot-settings)