Description
HDD password plaintext is stored in a UEFI variable.
Published: 2026-09-03
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to retrieve the HDD password stored in a UEFI variable in cleartext, potentially exposing the encryption key used to protect the hard drive. This results in a direct confidentiality breach, enabling the compromise of stored data if the password is used to decrypt the drive. The weakness is represented by CWE-256, indicating insecure data storage without proper encryption.

Affected Systems

The flaw exists in Insyde Software’s InsydeH2O firmware across multiple kernel families. Upgrades to kernel 5.1, 5.2, 5.3, 5.4, and 5.5 require firmware revisions 05.17.12, 05.27.12, 05.36.12, 05.43.51, and 05.51.51 respectively. Systems running older kernel builds with earlier firmware versions are impacted.

Risk and Exploitability

With a CVSS score of 8.2 the vulnerability is classified as high severity. The EPSS score is not available, and the issue is not listed in CISA KEV, suggesting no widely reported exploitation yet. The likely attack vector involves firmware-level access; an attacker who can interact with UEFI variables—either through physical access or compromised pre‑boot services—can read the plaintext password and leverage it to decrypt the disk.

Generated by OpenCVE AI on September 3, 2026 at 10:21 UTC.

Remediation

Vendor Solution

Kernel 5.1: Version 05.17.12 Kernel 5.2: Version 05.27.12 Kernel 5.3: Version 05.36.12 Kernel 5.4: Version 05.43.51 Kernel 5.5: Version 05.51.51


OpenCVE Recommended Actions

  • Update InsydeH2O firmware to the latest version released for the installed kernel—e.g., for kernel 5.4 install firmware 05.43.51 or newer
  • After the firmware update, adjust UEFI settings to disable any feature that stores HDD passwords in plaintext, ensuring the password is either removed or encrypted
  • Enforce physical security controls such as BIOS/UEFI password protection and limiting physical access to the machine to reduce unauthorized variable read

Generated by OpenCVE AI on September 3, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Insyde Software
Insyde Software insydeh2o
Vendors & Products Insyde Software
Insyde Software insydeh2o

Thu, 03 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description HDD password plaintext is stored in a UEFI variable.
Title HDD Password Stored In Plaintext
Weaknesses CWE-256
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Insyde Software Insydeh2o
cve-icon MITRE

Status: PUBLISHED

Assigner: Insyde

Published:

Updated: 2026-09-03T13:02:37.267Z

Reserved: 2021-08-10T19:30:25.949Z

Link: CVE-2021-38489

cve-icon Vulnrichment

Updated: 2026-09-03T13:02:33.657Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-03T13:04:10.943

Modified: 2026-09-03T18:09:03.317

Link: CVE-2021-38489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:33:29Z

Weaknesses
  • CWE-256

    Plaintext Storage of a Password