CVE-2021-38489

8.2

Insyde · InsydeH2O

InsydeH2O UEFI firmware stores hard drive passwords in plaintext within a UEFI variable, potentially allowing unauthorized access to sensitive data.

Executive summary

A critical security flaw in InsydeH2O firmware allows for the exposure of hard drive passwords in plaintext, posing a significant risk to data confidentiality.

Vulnerability

This vulnerability is categorized as Unprotected Storage of Credentials (CWE-256), where sensitive plaintext hard drive passwords are stored in UEFI variables. Successful exploitation requires high privileges (PR:H) to access the UEFI variable storage.

Business impact

The exposure of plaintext hard drive passwords undermines the fundamental encryption and access control mechanisms protecting stored data. With a CVSS score of 8.2, this vulnerability represents a high risk as it could lead to total compromise of confidentiality, integrity, and availability of data residing on affected hardware.

Remediation

Immediate Action: Update the affected InsydeH2O firmware to the versions specified in the vendor solution (Kernel 5.1: 05.17.12, 5.2: 05.27.12, 5.3: 05.36.12, 5.4: 05.43.51, 5.5: 05.51.51).

Proactive Monitoring: Monitor systems for unauthorized access to firmware settings or anomalous modifications to UEFI variables.

Compensating Controls: Implement full disk encryption at the operating system level, which may provide additional protection should the drive password be compromised.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high severity of this firmware-level vulnerability, IT administrators must prioritize the application of the provided security updates. Because this flaw involves low-level storage of credentials, immediate patching is necessary to ensure the integrity of the device boot and storage security chain.

Sources

Originally found and disclosed by Insyde Software would like to thank Binarly for reporting this issue., per the CVE Program record.