GPU VulnDB

Database/Firmware, BMC & network fabric

InsydeH2O: BIOS user and administrator password hashes exposed in runtime-readable UEFI variables

CVE-2021-43613Firmware, BMC & network fabriccurated

Impact

SysPasswordDxe leaves the user and administrator BIOS password hashes in UEFI variables that remain readable at OS runtime, so any local account with access to the efivars interface can read them and attempt offline cracking. Recovering the administrator password means being able to enter BIOS setup on that machine class and change boot order, Secure Boot state, IOMMU and virtualization settings, or SR-IOV and above-4G decoding options that GPU passthrough depends on - the settings an operator relies on to keep tenants apart. Insyde scores it scope-changed at 6.5 for exactly that reason: the disclosure happens in the OS, the consequence lands in firmware. Published to NVD on 2026-09-03 from Insyde advisory SA-2022027, so this is an old fix surfacing late rather than new exposure; the practical question is whether the boards you actually run carry an unpatched InsydeH2O build.

Who can reach it

Local authenticated user on the host with the ability to read runtime UEFI variables (PR:L) - on Linux, read access to /sys/firmware/efi/efivars. No physical access and no reboot needed to obtain the hashes; using them requires reaching BIOS setup afterwards.

What to do

Insyde's fix reaches you only through the board or system OEM's BIOS release - Insyde licenses InsydeH2O to OEMs and does not ship end-user updates. Check with the server vendor whether the platform uses InsydeH2O and which BIOS build carries SA-2022027, then flash it, which means taking the node out of service for a firmware update and reboot. If your fleet's boards are AMI or a different IBV, this does not apply. In the meantime, restrict local host accounts on affected machines and treat the BIOS setup password as compromised rather than as a control you can rely on.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.