VulnerabilityModified
CVE-2005-4175
Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.
LOW 2.1EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Affected
- insyde/insyde bios
- Source
- cve@mitre.org
References
- http://www.ivizsecurity.com/preboot-patch.html
- http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf
- http://www.kb.cert.org/vuls/id/847537Third Party Advisory, US Government Resource
- http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt
- http://www.securityfocus.com/archive/1/419610/100/0/threaded
- http://www.securityfocus.com/bid/15751
- http://www.ivizsecurity.com/preboot-patch.html
- http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf
- http://www.kb.cert.org/vuls/id/847537Third Party Advisory, US Government Resource
- http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt
- http://www.securityfocus.com/archive/1/419610/100/0/threaded
- http://www.securityfocus.com/bid/15751
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.