CVE-2008-3898
Status: ModifiedLow (2.1)—
Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.
CVSS
- Version: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N
- Base score: 2.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.35%
- Percentile among all scored CVEs: 26
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-200
References
- http://secunia.com/advisories/31605
- http://securityreason.com/securityalert/4213
- http://www.ivizsecurity.com/preboot-patch.html
- http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf
- http://www.ivizsecurity.com/security-advisory-iviz-sr-0807.html
- http://www.securityfocus.com/archive/1/495803/100/0/threaded
- http://www.securityfocus.com/bid/30818
- http://secunia.com/advisories/31605
- http://securityreason.com/securityalert/4213
- http://www.ivizsecurity.com/preboot-patch.html
- http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf
- http://www.ivizsecurity.com/security-advisory-iviz-sr-0807.html
- http://www.securityfocus.com/archive/1/495803/100/0/threaded
- http://www.securityfocus.com/bid/30818
Raw JSON (NVD)
Show
{
"id": "CVE-2008-3898",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-09-03T14:12:00.000",
"references": [
{
"url": "http://secunia.com/advisories/31605",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/4213",
"source": "cve@mitre.org"
},
{
"url": "http://www.ivizsecurity.com/preboot-patch.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf",
"source": "cve@mitre.org"
},
{
"url": "http://www.ivizsecurity.com/security-advisory-iviz-sr-0807.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/495803/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/30818",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/31605",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/4213",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ivizsecurity.com/preboot-patch.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ivizsecurity.com/security-advisory-iviz-sr-0807.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/495803/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/30818",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer."
},
{
"lang": "es",
"value": "Secu Star DriveCrypt Plus Pack 3.9 alamcena contraseñas de autenticación de pre-arranque en el búfer BIOS Keyboard y no limpia este búfer antes y después del uso, lo cual permite a usuarios locales obtener información sensible leyendo las localizaciones de memoria física asociadas con este búfer."
}
],
"lastModified": "2026-06-16T22:56:45.963",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:secustar:drivecrypt_plus_pack:3.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03119419-5631-4E22-8521-BEC78D62EE3E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}