CVE-2023-31041

HIGH

Insyde InsydeH2O 5.0-5.5 - Cleartext Storage of Sensitive Information in SysPasswordDxe

Title source: llm
STIX 2.1

Description

An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0031
EPSS Percentile 22.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (6)
insyde/insydeh2o 5.0
insyde/insydeh2o 5.1
insyde/insydeh2o 5.2
insyde/insydeh2o 5.3
insyde/insydeh2o 5.4
insyde/insydeh2o 5.5
Published Aug 14, 2023
Tracked Since Feb 18, 2026