Impact
The vulnerability allows an attacker to retrieve the HDD password stored in a UEFI variable in cleartext, potentially exposing the encryption key used to protect the hard drive. This results in a direct confidentiality breach, enabling the compromise of stored data if the password is used to decrypt the drive. The weakness is represented by CWE-256, indicating insecure data storage without proper encryption.
Affected Systems
The flaw exists in Insyde Software’s InsydeH2O firmware across multiple kernel families. Upgrades to kernel 5.1, 5.2, 5.3, 5.4, and 5.5 require firmware revisions 05.17.12, 05.27.12, 05.36.12, 05.43.51, and 05.51.51 respectively. Systems running older kernel builds with earlier firmware versions are impacted.
Risk and Exploitability
With a CVSS score of 8.2 the vulnerability is classified as high severity. The EPSS score is not available, and the issue is not listed in CISA KEV, suggesting no widely reported exploitation yet. The likely attack vector involves firmware-level access; an attacker who can interact with UEFI variables—either through physical access or compromised pre‑boot services—can read the plaintext password and leverage it to decrypt the disk.
OpenCVE Enrichment