SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2021-38489

HIGH · CVSS 8.2 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists where HDD passwords are stored in plaintext within a UEFI variable, potentially allowing unauthorized access to sensitive data. This poses a significant risk to systems that rely on UEFI for security, as attackers could exploit this weakness to retrieve and misuse stored passwords. Organizations utilizing UEFI-enabled devices should prioritize remediation efforts to mitigate the risk of unauthorized data access.

CVE
CVE-2021-38489
Severity
HIGH
CVSS
8.2
EPSS
0.12%

Original NVD Description

HDD password plaintext is stored in a UEFI variable.