8.2
CWE
276
Advisory Published
Updated

CVE-2022-4020: Acer Aspire BIOS vulnerability

First published: Mon Nov 28 2022(Updated: )

Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.

Credit: security@eset.com

Affected SoftwareAffected VersionHow to fix
Acer Aspire A315-22g Firmware
Acer Aspire A315-22g
Acer Aspire A115-21 Firmware
Acer Aspire A115-21
Acer Aspire A315-22 Firmware
Acer Aspire A315-22
Acer Extensa Ex215-21 Firmware
Acer Extensa Ex215-21
Acer Extensa Ex215-21g Firmware
Acer Extensa Ex215-21g

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2022-4020?

    CVE-2022-4020 is a vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices.

  • How does CVE-2022-4020 impact Acer Aspire A315-22g Firmware?

    CVE-2022-4020 may allow an attacker with elevated privileges to modify UEFI Secure Boot settings on Acer Aspire A315-22g Firmware.

  • Is Acer Aspire A315-22g vulnerable to CVE-2022-4020?

    No, Acer Aspire A315-22g is not vulnerable to CVE-2022-4020.

  • How severe is CVE-2022-4020?

    CVE-2022-4020 has a severity rating of 8.2 (high).

  • How can I fix CVE-2022-4020?

    Acer has released a security update to address the vulnerability. Please refer to the following link for more information: [link](https://community.acer.com/en/kb/articles/15520-security-vulnerability-regarding-vulnerability-that-may-allow-changes-to-secure-boot-settings)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203