CVE-2005-4176
Estado: ModificadaBaja (2.1)—💥 Exploit
AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 2.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.26%
- Percentil entre todas las CVEs puntuadas: 69
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Multiple Vendor BIOS - Keyboard Buffer Password Persistence (1) (6/12/2005)
- Publicado en Exploit-DB · Multiple Vendor BIOS - Keyboard Buffer Password Persistence (2) (6/12/2005)
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- NVD-CWE-Other
Referencias
- http://www.ivizsecurity.com/preboot-patch.html
- http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf
- http://www.kb.cert.org/vuls/id/847537
- http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt
- http://www.securityfocus.com/archive/1/419610/100/0/threaded
- http://www.securityfocus.com/bid/15751
- http://www.ivizsecurity.com/preboot-patch.html
- http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf
- http://www.kb.cert.org/vuls/id/847537
- http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt
- http://www.securityfocus.com/archive/1/419610/100/0/threaded
- http://www.securityfocus.com/bid/15751
JSON original (NVD)
Mostrar
{
"id": "CVE-2005-4176",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-12-11T21:03:00.000",
"references": [
{
"url": "http://www.ivizsecurity.com/preboot-patch.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf",
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/847537",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/419610/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/15751",
"source": "cve@mitre.org"
},
{
"url": "http://www.ivizsecurity.com/preboot-patch.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/847537",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/419610/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/15751",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory."
},
{
"lang": "es",
"value": "AWARD Bios Modular 4.50pg no borra el búfer del teclado después de leer la contraseña de la BIOS durante el arranque del sistema, lo que permite a administradores o usuarios locales leer la contraseña directamente de la memoria física."
}
],
"lastModified": "2026-06-16T22:18:18.957",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:award:award_bios_modular:4.50pg:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "39E9C36E-50B6-4435-B867-3BE73DC511DD"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}