CVE-2021-38489
8.2Insyde · InsydeH2O
InsydeH2O UEFI firmware stores hard drive passwords in plaintext within a UEFI variable, potentially allowing unauthorized access to sensitive data.
Executive summary
A critical security flaw in InsydeH2O firmware allows for the exposure of hard drive passwords in plaintext, posing a significant risk to data confidentiality.
Vulnerability
This vulnerability is categorized as Unprotected Storage of Credentials (CWE-256), where sensitive plaintext hard drive passwords are stored in UEFI variables. Successful exploitation requires high privileges (PR:H) to access the UEFI variable storage.
Business impact
The exposure of plaintext hard drive passwords undermines the fundamental encryption and access control mechanisms protecting stored data. With a CVSS score of 8.2, this vulnerability represents a high risk as it could lead to total compromise of confidentiality, integrity, and availability of data residing on affected hardware.
Remediation
Immediate Action: Update the affected InsydeH2O firmware to the versions specified in the vendor solution (Kernel 5.1: 05.17.12, 5.2: 05.27.12, 5.3: 05.36.12, 5.4: 05.43.51, 5.5: 05.51.51).
Proactive Monitoring: Monitor systems for unauthorized access to firmware settings or anomalous modifications to UEFI variables.
Compensating Controls: Implement full disk encryption at the operating system level, which may provide additional protection should the drive password be compromised.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity of this firmware-level vulnerability, IT administrators must prioritize the application of the provided security updates. Because this flaw involves low-level storage of credentials, immediate patching is necessary to ensure the integrity of the device boot and storage security chain.
Sources
Originally found and disclosed by Insyde Software would like to thank Binarly for reporting this issue., per the CVE Program record.