HDD Password Retrieval Vulnerability in ARM-based Systems by Insyde Software
CVE-2026-8810

6.9MEDIUM

Key Information:

Vendor
CVE Published:
19 August 2026

What is CVE-2026-8810?

A security weakness exists in ARM architecture that could enable an unauthorized attacker to access and retrieve the HDD Password stored in UEFI variables. This vulnerability poses a risk to the confidentiality of sensitive data, emphasizing the need for robust security measures in firmware development.

Affected Version(s)

InsydeH2O, InsydeH2O ARM ARM Kernel 5.6 < 05.63.21

InsydeH2O, InsydeH2O ARM ARM Kernel 5.7 < 05.72.21

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.