Insyde Software InsydeH2O

5 known vulnerabilities in Insyde Software InsydeH2O, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-6485 CVSS 8.2 high UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
  • CVE-2026-12855 CVSS 8.2 high Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP…
  • CVE-2021-43614 CVSS 6.7 medium Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure.
  • CVE-2021-43613 CVSS 6.5 medium An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI…
  • CVE-2021-38489 CVSS 8.2 high HDD password plaintext is stored in a UEFI variable.