CVE-2008-3900
Summary
| CVE | CVE-2008-3900 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-09-03 14:12:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Intel firmware PE94510M.86A.0050.2007.0710.1559 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| iViZ - On Demand Automated Penetration Testing | af854a3a-2127-422b-91ae-364da2661108 | www.ivizsecurity.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - Intel BIOS Discloses Boot Password to Local users | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf | af854a3a-2127-422b-91ae-364da2661108 | www.ivizsecurity.com | |
| CERT Vulnerability Notes Database | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| SecurityReason - Intel BIOS Plain Text Password Disclosure | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.