CVE-2026-8810
6.9
CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Summary
On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Insyde Software | InsydeH2O, InsydeH2O ARM | Kernel 5.6 < 05.63.21 | affected |
| Insyde Software | InsydeH2O, InsydeH2O ARM | Kernel 5.7 < 05.72.21 | affected |
Weaknesses
- CWE-522: CWE-522: Insufficiently Protected Credentials
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.