CVE-2002-2059
Summary
| CVE | CVE-2002-2059 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | BIOS D845BG, D845HV, D845PT and D845WN on Intel motherboards does not properly restrict access to configuration information when BIOS passwords are enabled, which could allow local users to change the default boot device via the F8 key. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Intel | D845bg Motherboard | p01-0012 | All | All | All |
| Hardware | Intel | D845bg Motherboard | p02-0015 | All | All | All |
| Hardware | Intel | D845bg Motherboard | p03-0021 | All | All | All |
| Hardware | Intel | D845bg Motherboard | p04-0023 | All | All | All |
| Hardware | Intel | D845bg Motherboard | p05-0024 | All | All | All |
| Hardware | Intel | D845hv Motherboard | p04-0018 | All | All | All |
| Hardware | Intel | D845hv Motherboard | p05-0022 | All | All | All |
| Hardware | Intel | D845hv Motherboard | p06-0024 | All | All | All |
| Hardware | Intel | D845hv Motherboard | p07-0029 | All | All | All |
| Hardware | Intel | D845hv Motherboard | p08-0031 | All | All | All |
| Hardware | Intel | D845hv Motherboard | p09-0035 | All | All | All |
| Hardware | Intel | D845hv Motherboard | p10-0038 | All | All | All |
| Hardware | Intel | D845hv Motherboard | p11-0040 | All | All | All |
| Hardware | Intel | D845pt Motherboard | p01-0012 | All | All | All |
| Hardware | Intel | D845pt Motherboard | p02-0015 | All | All | All |
| Hardware | Intel | D845pt Motherboard | p03-0021 | All | All | All |
| Hardware | Intel | D845pt Motherboard | p04-0023 | All | All | All |
| Hardware | Intel | D845pt Motherboard | p05-0024 | All | All | All |
| Hardware | Intel | D845wn Motherboard | p04-0018 | All | All | All |
| Hardware | Intel | D845wn Motherboard | p06-0024 | All | All | All |
| Hardware | Intel | D845wn Motherboard | p07-0029 | All | All | All |
| Hardware | Intel | D845wn Motherboard | p08-0031 | All | All | All |
| Hardware | Intel | D845wn Motherboard | p09-0035 | All | All | All |
| Hardware | Intel | D845wn Motherboard | p10-0038 | All | All | All |
| Hardware | Intel | D845wn Motherboard | p11-0040 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| download.intel.com/design/motherbd/bg/P06-0027.pdf | af854a3a-2127-422b-91ae-364da2661108 | download.intel.com | |
| download.intel.com/design/motherbd/pt/P06-0027.pdf | af854a3a-2127-422b-91ae-364da2661108 | download.intel.com | |
| Intel D845 Motherboard BIOS Series Arbitrary Boot Media Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Neohapsis Archives - Bugtraq - Intel D845HV/WN/PT series motherboard vulnerability - From [email protected] | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit |
| ISS X-Force Database: intel-d845-change-device (8998): Intel D845 series motherboards could allow an attacker to bypass the BIOS password and change the boot device | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Patch |
| download.intel.com/design/motherbd/wn/P12-0041d.pdf | af854a3a-2127-422b-91ae-364da2661108 | download.intel.com | |
| download.intel.com/design/motherbd/hv/P12-0041d.pdf | af854a3a-2127-422b-91ae-364da2661108 | download.intel.com | |
| archives.neohapsis.com/archives/bugtraq/2002-05/0017.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.