Database/Firmware, BMC & network fabric

InsydeH2O: HDD password is stored in plaintext in a UEFI variable readable from the OS
Impact
The drive password is written to a UEFI variable in cleartext, so anyone able to read UEFI variables from the running operating system recovers it. On a server that means a privileged OS account - or anyone who obtains one during the machine's life - can unlock the drive independently of the platform, and the secret survives OS reinstall because it lives in NVRAM. For a datacenter this matters most at decommission and RMA time: a chassis that leaves the floor still carries the drive password in firmware storage. Scope is marked changed in the CVSS vector, reflecting that the disclosure crosses from the OS into the platform. This is a 2021 identifier only now published to NVD; check whether your OEM's firmware already carries the fix.
Who can reach it
Local access with high privileges on the host operating system - enough to read UEFI variables. No physical access and no network path required.
What to do
Apply the OEM BIOS/UEFI update carrying Insyde's fix (advisory SA-2022025); Insyde ships to OEMs, so the actual fixed version is the server vendor's firmware release, not an Insyde build number. This is a firmware flash with the node out of service - drain the GPU workloads, flash, reboot, and verify. Rotate any drive passwords that were set on affected firmware, since they must be assumed disclosed.
References
Related entries
- GRUB2 (shim_lock verifier): The shim_lock verifier let non-kernel files through, so an attacker could get unsignedCVE-2022-28735 · GRUB2 (shim_lock verifier)High
- shim (handle_image PE loader): Buffer overflow in shim's own image loaderCVE-2022-28737 · shim (handle_image PE loader)High
- Insyde InsydeH2O (UsbCoreDxe, untrusted pointer use): UsbCoreDxe uses pointers it was handed without establishing theyCVE-2022-29275 · Insyde InsydeH2O (UsbCoreDxe, untrusted pointer use)High
- Insyde InsydeH2O (AhciBusDxe, untrusted SMI inputs): SMI functions in the AHCI/SATA driver consume untrusted inputsCVE-2022-29276 · Insyde InsydeH2O (AhciBusDxe, untrusted SMI inputs)High
- Insyde InsydeH2O (NvmExpressDxe, incorrect pointer checks): The NVMe driver's pointer validation is wrong, allowingCVE-2022-29278 · Insyde InsydeH2O (NvmExpressDxe, incorrect pointer checks)High
- Insyde InsydeH2O (SdHostDriver and SdMmcDevice, untrusted pointer use): One advisory covering both SD layers: untrustedCVE-2022-29279 · Insyde InsydeH2O (SdHostDriver and SdMmcDevice, untrusted pointer use)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.