CyberRota Analysis
AI-GeneratedA vulnerability exists where HDD passwords are stored in plaintext within a UEFI variable, potentially allowing unauthorized access to sensitive data. This poses a significant risk to systems that rely on UEFI for security, as attackers could exploit this weakness to retrieve and misuse stored passwords. Organizations utilizing UEFI-enabled devices should prioritize remediation efforts to mitigate the risk of unauthorized data access.
CVE
CVE-2021-38489
Severity
HIGH
CVSS
8.2
EPSS
0.12%
Original NVD Description
HDD password plaintext is stored in a UEFI variable.