Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-43613 1 Insyde Software 1 Insydeh2o 2026-09-03 6.5 Medium
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
CVE-2021-43614 1 Insyde Software 1 Insydeh2o 2026-09-03 6.7 Medium
Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure.
CVE-2021-38489 1 Insyde Software 1 Insydeh2o 2026-09-03 8.2 High
HDD password plaintext is stored in a UEFI variable.