CVE-2026-8810
HDD Password leakage vulnerability
CVSS Score
6.9
EPSS Score
0.0%
EPSS Percentile
0th
On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
| CWE | CWE-522 |
| Vendor | insyde software |
| Product | insydeh2o, insydeh2o arm |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for insyde software insydeh2o, insydeh2o arm
Be the first to know when new medium vulnerabilities affecting insyde software insydeh2o, insydeh2o arm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H Attack Vector
Physical
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Insyde Software / InsydeH2O, InsydeH2O ARM
Kernel 5.6 < 05.63.21 Kernel 5.7 < 05.72.21