PT-2005-4875 · Award · Award Bios Modular
Published
2005-12-11
·
Updated
2018-10-19
·
CVE-2005-4176
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AWARD Bios Modular version 4.50pg
Description
The issue concerns the failure to clear the keyboard buffer after reading the BIOS password during system startup. This allows local administrators or users to read the password directly from physical memory.
Recommendations
For AWARD Bios Modular version 4.50pg, consider changing the BIOS password to a new, complex password and ensuring physical security of the system to minimize the risk of exploitation. Additionally, restrict access to the system's physical memory to prevent unauthorized password reading.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Award Bios Modular