CVE-2026-8810 PUBLISHED

HDD Password leakage vulnerability

Assigner: Insyde
Reserved: 18.05.2026 Published: 19.08.2026 Updated: 19.08.2026

On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.

Metrics

CVSS Vector: CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS Score: 6.9

Product Status

Vendor Insyde Software
Product InsydeH2O, InsydeH2O ARM
Versions Default: unaffected
  • affected from Kernel 5.6 to 05.63.21 (excl.)
  • affected from Kernel 5.7 to 05.72.21 (excl.)

References

Problem Types

  • CWE-522: Insufficiently Protected Credentials CWE