ivizsecurity.com
http://www.ivizsecurity.com/preboot-patch.html CVE-2005-4176
Multiple Vendor BIOS - Keyboard Buffer Password Persistence (1)
Record summary
CVE-2005-4176 has a selected CVSS score of 2.1; EIP currently links 2 catalogued exploits.
Description
AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBMultiple Vendor BIOS - Keyboard Buffer Password Persistence (1)ExploitDB exploitby EndrazineNot analyzed1 file
ExploitDBMultiple Vendor BIOS - Keyboard Buffer Password Persistence (2)ExploitDB exploitby EndrazineNot analyzed1 file
References
7ivizsecurity.com
http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf VU#847537Third-party advisory
http://www.kb.cert.org/vuls/id/847537 pulltheplug.org
http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt 20051213 Bios Information Leakagemailing list
http://www.securityfocus.com/archive/1/419610/100/0/threaded 15751vdb entry
http://www.securityfocus.com/bid/15751 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-4176