VulnerabilityUndergoing Analysis
CVE-2021-43613
User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
MEDIUM 6.5EPSS 0.11%
Does this matter?
Lower severity and a low EPSS score (0.11%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- EPSS
- 0.11% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Source
- 8338d8cb-57f7-4252-abc0-96fd13e98d21
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.