Database/Firmware, BMC & network fabric

Insyde InsydeH2O on ARM platforms (HDD password storage in UEFI variables): HDD passwords are recoverable from UEFI
Impact
HDD passwords are recoverable from UEFI variables on affected ARM platforms - insufficiently protected credentials, in CWE terms. The operator concern is drive-level secrets surviving in firmware storage where the next person to hold the box can read them, which matters for any fleet where drive locking is part of the between-tenant wipe story, and for ARM-based nodes appearing in AI inference and edge fleets.
Who can reach it
Requires physical access plus local privilege and user interaction per Insyde's own scoring - so this is a returned-hardware, decommissioning, or colo-access risk rather than a remote one.
What to do
OEM firmware update on Insyde kernel 5.6 / 05.63.21 or 5.7 / 05.72.21. Firmware flash, reboot per node. Advisory dated 2026-08-18, so OEM images are not yet widely available. Operational mitigation that does not wait for the flash: do not rely on ATA HDD passwords as the confidentiality control on affected ARM platforms - use self-encrypting-drive keys or software full-disk encryption with keys held off the node, and cryptographically erase rather than password-lock drives at decommission.
References
Related entries
- Dell iDRAC (u-boot): Improper error handling grants access to the u-boot shell — pre-BMC-OS control, i.eCVE-2018-15776 · Dell iDRAC (u-boot)Medium
- Intel SSD DC S4500 and SSD DC S4600 series firmware before SCV10150 - improper authentication: Improper authenticationCVE-2018-18095 · Intel SSD DC S4500 and SSD DC S4600 series firmware before SCV10150 - improper authenticationMedium
- Intel Boot Guard in Intel CSME / TXE / SPS: Insecure default initialisation in Boot Guard means the S3 resume path doesCVE-2020-8705 · Intel Boot Guard in Intel CSME / TXE / SPSMedium
- Intel / Solidigm SSD, SSD DC and Optane SSD firmwareCVE-2021-33077 · Intel / Solidigm SSD, SSD DC and Optane SSD firmware - control-flow flaw and uncleared debug data reachable over…Medium
- Intel Boot Guard and Intel TXT (hardware debug / INIT): Hardware debug modes and processor INIT handling can overrideCVE-2022-0004 · Intel Boot Guard and Intel TXT (hardware debug / INIT)Medium
- AMD Secure Processor secure boot - voltage fault injection (AMD-SB-4005): Voltage fault injection against the ASPCVE-2023-20589 · AMD Secure Processor secure boot - voltage fault injection (AMD-SB-4005)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.