Impact
The vulnerability lies in the architecture of the HDD password mechanism on ARM-based UEFI platforms. An attacker capable of accessing the UEFI variable storage could read the stored HDD password, leaking the credential used to protect data disks. This discloses sensitive authentication information, potentially allowing an adversary to bypass disk encryption or access encrypted data. The weakness maps to CWE‑522, which describes the failure to secure the storage of credentials.
Affected Systems
The flaw affects Insyde Software’s UEFI implementations named InsydeH2O and InsydeH2O ARM. All builds of these firmware components that run on ARM hardware and use the legacy HDD password storage mechanism are susceptible. No specific version range is disclosed, so any current or previous release is considered at risk until a vendor update removes the vulnerable design.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that accessing the UEFI variable store typically requires local or privileged access, so the attack vector is likely physical or local. Once the credential is extracted, an attacker could mount offline or on‑the‑fly attacks against encrypted drives, undermining confidentiality and integrity of stored data.
OpenCVE Enrichment