GPU VulnDB

Database/Firmware, BMC & network fabric

InsydeH2O: HDD password is stored in plaintext in a UEFI variable readable from the OS

CVE-2021-38489Firmware, BMC & network fabriccurated

Impact

The drive password is written to a UEFI variable in cleartext, so anyone able to read UEFI variables from the running operating system recovers it. On a server that means a privileged OS account - or anyone who obtains one during the machine's life - can unlock the drive independently of the platform, and the secret survives OS reinstall because it lives in NVRAM. For a datacenter this matters most at decommission and RMA time: a chassis that leaves the floor still carries the drive password in firmware storage. Scope is marked changed in the CVSS vector, reflecting that the disclosure crosses from the OS into the platform. This is a 2021 identifier only now published to NVD; check whether your OEM's firmware already carries the fix.

Who can reach it

Local access with high privileges on the host operating system - enough to read UEFI variables. No physical access and no network path required.

What to do

Apply the OEM BIOS/UEFI update carrying Insyde's fix (advisory SA-2022025); Insyde ships to OEMs, so the actual fixed version is the server vendor's firmware release, not an Insyde build number. This is a firmware flash with the node out of service - drain the GPU workloads, flash, reboot, and verify. Rotate any drive passwords that were set on affected firmware, since they must be assumed disclosed.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.