Impact
An issue in SysPasswordDxe of InsydeH2O exposes user and administrator password hashes in runtime UEFI variables, allowing an attacker with access to those variables to obtain credentials and elevate privileges. This flaw is an access control weakness, as identified by CWE-732.
Affected Systems
The vulnerability affects Insyde Software's InsydeH2O firmware across Kernel versions 5.1 through 5.5. Specifically, the following firmware releases contain the flaw: Kernel 5.1 version 05.17.09; Kernel 5.2 version 05.27.09; Kernel 5.3 version 05.36.09; Kernel 5.4 version 05.44.09; and Kernel 5.5 version 05.52.09.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an adversary with physical or remote firmware access who can read the exposed UEFI variables; local machine access would be sufficient to retrieve the hashes. Once obtained, these credentials enable escalation of privilege to administrative levels.
OpenCVE Enrichment