6.5
CVE-2021-43613
- EPSS 0.11%
- Veröffentlicht 03.09.2026 02:05:35
- Zuletzt bearbeitet 03.09.2026 18:09:03
- Erkennungen
SysPasswordDxe: Password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerInsyde Software
≫
Produkt
InsydeH2O
Default Statusunaffected
Version
See in the Solution
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.016 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 8338d8cb-57f7-4252-abc0-96fd13e98d21 | 6.5 | 2 | 4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
https://www.insyde.com/security-pledge/sa-2022027/