Description
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.
Related CPE's
a
insyde
insydeh2o
6
References
https://www.insyde.com/security-pledge/SA-2023047
Vendor Advisory
https://www.insyde.com/security-pledge/SA-2023047
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
7.5 · High
Information
Source identifier
Vulnerability status
Modified
Published
2023-08-14T13:15:12.237Z
2 years agoLast modified
2024-11-21T07:01:18.313Z
1 year ago