CVE-2021-43613
Received Received - Intake

InsydeH2O UEFI Password Hash Exposure in SysPasswordDxe

Vulnerability report for CVE-2021-43613, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: Insyde

Description

An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
insyde insydeh2o From 5.1 (inc) to 5.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Insyde Software's InsydeH2O firmware where user and administrator password hashes are exposed in runtime UEFI variables. It is associated with the SysPasswordDxe driver and can lead to privilege escalation attacks.

Detection Guidance

Detecting this vulnerability requires checking for exposed password hashes in UEFI variables. Insyde recommends inspecting runtime UEFI variables for SysPasswordDxe-related entries. No specific commands are provided in the resources, but you may use tools like 'efivar' on Linux to list UEFI variables and search for suspicious entries.

Impact Analysis

An attacker could exploit this vulnerability to gain elevated privileges on a system by accessing password hashes stored in UEFI variables. This could allow unauthorized access to sensitive data or control over the affected device.

Mitigation Strategies

Update InsydeH2O firmware to patched kernel versions (5.1 05.17.03, 5.2 05.27.03, 5.3 05.36.03, 5.4 05.43.46, or 5.5 05.51.46). If updating is not possible, restrict access to UEFI variables and disable unnecessary drivers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2021-43613. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart