ZeroHour

CVE-2021-38489

mass

Plaintext HDD password disclosure in Insyde Software InsydeH2O UEFI firmware

CVSS 3.1
8.2 high
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2021-38489 is a plaintext password storage flaw (CWE-256) in Insyde Software's InsydeH2O UEFI firmware: when the HDD (ATA) password feature is used, the password is written unencrypted into a UEFI firmware variable instead of being stored in hashed or obfuscated form. An attacker with local high-level privileges, such as an OS administrator or admin-level malware, can read the firmware variable store and recover the drive's HDD password in clear text. Armed with that password, the attacker can bypass or alter the drive's password protection, for example by unlocking the disk or changing or clearing its password, potentially reaching data the HDD password was meant to protect, which is why the CVSS 3.1 score of 8.2 marks changed scope with high confidentiality, integrity, and availability impact. Any PC that ships InsydeH2O-based firmware and has the HDD password feature in use is potentially affected, across the many OEM laptops and desktops that use this firmware, though the available data does not specify exact affected version ranges. No exploitation has been reported: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.1% chance of exploitation in the next 30 days.

What to do: Contact your OEM for BIOS/UEFI updates incorporating Insyde Software's fix, since no specific fixed version numbers were published and patches flow through OEM firmware releases. Do not rely solely on HDD/ATA passwords for data protection; layer OS-based or hardware full-disk encryption (for example BitLocker or self-encrypting-drive management). To check exposure, dump the UEFI variable store with elevated privileges (for example with CHIPSEC or efivars) and confirm whether the HDD password is stored in clear text.

Affected
Insyde Software InsydeH2O UEFI firmware
Estimated exposure
masstens of millions of OEM PCs (InsydeH2O is a top-tier UEFI firmware stack; only systems where an HDD password is set are materially exposed) — InsydeH2O is one of the dominant PC UEFI firmware suppliers shipped by major laptop and desktop OEMs, implying a very large installed base, but unspecified version ranges and the requirement that the user actually set an HDD password make…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

HDD password plaintext is stored in a UEFI variable.

Weakness
CWE-256
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.