First published: Sun Dec 11 2005(Updated: )
Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde Insyde Bios | =v190 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4175 is considered a medium severity vulnerability due to the potential for unauthorized access to sensitive information.
CVE-2005-4175 allows local users to read the BIOS password from physical memory, compromising the system's security.
To fix CVE-2005-4175, update to a version of the Insyde BIOS that addresses this vulnerability.
CVE-2005-4175 affects users of Insyde BIOS version 190, specifically those with physical access to the system.
The potential consequences of CVE-2005-4175 include unauthorized access to the BIOS settings and exposure of the BIOS password.