Description
On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
Published: 2026-08-19
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the architecture of the HDD password mechanism on ARM-based UEFI platforms. An attacker capable of accessing the UEFI variable storage could read the stored HDD password, leaking the credential used to protect data disks. This discloses sensitive authentication information, potentially allowing an adversary to bypass disk encryption or access encrypted data. The weakness maps to CWE‑522, which describes the failure to secure the storage of credentials.

Affected Systems

The flaw affects Insyde Software’s UEFI implementations named InsydeH2O and InsydeH2O ARM. All builds of these firmware components that run on ARM hardware and use the legacy HDD password storage mechanism are susceptible. No specific version range is disclosed, so any current or previous release is considered at risk until a vendor update removes the vulnerable design.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that accessing the UEFI variable store typically requires local or privileged access, so the attack vector is likely physical or local. Once the credential is extracted, an attacker could mount offline or on‑the‑fly attacks against encrypted drives, undermining confidentiality and integrity of stored data.

Generated by OpenCVE AI on August 20, 2026 at 19:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the latest firmware updates for InsydeH2O and InsydeH2O ARM that eliminate the vulnerable HDD password storage design from the vendor’s security pledge page.
  • Enable secure boot to enforce firmware authenticity and prevent tampering.
  • Until a patched firmware version is available, disable the HDD password feature or switch to an alternative disk encryption solution that does not rely on UEFI variable storage, and limit physical access to the device to trusted personnel.

Generated by OpenCVE AI on August 20, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Insyde
Insyde insydeh2o
Vendors & Products Insyde
Insyde insydeh2o

Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
Title HDD Password leakage vulnerability
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 6.9, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Insyde Insydeh2o
cve-icon MITRE

Status: PUBLISHED

Assigner: Insyde

Published:

Updated: 2026-08-20T15:36:47.245Z

Reserved: 2026-05-18T07:16:10.503Z

Link: CVE-2026-8810

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T06:17:43.293

Modified: 2026-08-31T19:27:23.020

Link: CVE-2026-8810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:31:36Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials