Executive brief
Insyde InsydeH2O is firmware used in many enterprise and OEM systems to manage hardware initialization and security. A vulnerability allows high-privileged users to recover HDD passwords stored unencrypted in UEFI firmware variables, potentially exposing encrypted drives and sensitive data to physical attackers or privileged insiders with system access.
Technical details
The vulnerability is a credentials exposure flaw in the HddPasswordPei driver of Insyde InsydeH2O firmware. HDD passwords are stored in plaintext within UEFI variables, accessible to users with high-level privileges. The attack vector is local with high privilege requirements; an attacker with elevated system access or physical access to the system can read UEFI variables to extract the HDD password in plaintext. Insyde released patches in February 2022 across multiple kernel versions (5.1 through 5.5), available in the security advisory INSYDE-SA-2022025.
Affected products
- Insyde InsydeH2O Kernel 5.1 before 05.17.03, Kernel 5.2 before 05.27.03, Kernel 5.3 before 05.36.03, Kernel 5.4 before 05.43.51, Kernel 5.5 before 05.51.51
Timeline
- 2022-02-21: advisory: INSYDE-SA-2022025 published with patch information
- 2026-09-03: other: NVD entry published