An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
Attack Parameters
Impact Assessment
CVSS Vector v3.1
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days