Vulnerabilities > CVE-2005-4176

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
award
exploit available

Summary

AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.

Vulnerable Configurations

Part Description Count
Hardware
Award
1

Exploit-Db

  • descriptionMultiple Vendor BIOS Keyboard Buffer Password Persistence Weakness (1). CVE-2005-4176 . Local exploit for windows platform
    idEDB-ID:26752
    last seen2016-02-03
    modified2005-12-06
    published2005-12-06
    reporterEndrazine
    sourcehttps://www.exploit-db.com/download/26752/
    titleMultiple Vendor BIOS Keyboard Buffer Password Persistence Weakness 1
  • descriptionMultiple Vendor BIOS Keyboard Buffer Password Persistence Weakness (2). CVE-2005-4176 . Local exploit for unix platform
    idEDB-ID:26753
    last seen2016-02-03
    modified2005-12-06
    published2005-12-06
    reporterEndrazine
    sourcehttps://www.exploit-db.com/download/26753/
    titleMultiple Vendor BIOS Keyboard Buffer Password Persistence Weakness 2