CVE-2021-38489: HDD Password Stored In Plaintext
Published Sep 3, 2026
·Updated
HDD password plaintext is stored in a UEFI variable.
Event History
Sep 3, 2026
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The CVSS vector indicates local access and high privileges are required. This is not described as remotely exploitable by an unauthenticated attacker.
2
Does exploitation require user interaction?
No. The CVSS vector indicates that no user interaction is required once the attacker has the necessary local high privileges.
3
What impact is indicated if the issue is exploited?
The supplied CVSS metrics rate confidentiality, integrity, and availability impact as high, with scope changed.