{"api_version":"1","generated_at":"2026-07-23T05:41:57+00:00","cve":"CVE-2005-4175","urls":{"html":"https://cve.report/CVE-2005-4175","api":"https://cve.report/api/cve/CVE-2005-4175.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4175","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4175"},"summary":{"title":"CVE-2005-4175","description":"Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-11 21:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/847537","name":"http://www.kb.cert.org/vuls/id/847537","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"CERT Vulnerability Notes Database","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.securityfocus.com/archive/1/419610/100/0/threaded","name":"http://www.securityfocus.com/archive/1/419610/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ivizsecurity.com/preboot-patch.html","name":"http://www.ivizsecurity.com/preboot-patch.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"iViZ - On Demand Automated Penetration Testing","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15751","name":"http://www.securityfocus.com/bid/15751","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple Vendor BIOS Keyboard Buffer Password Persistence Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt","name":"http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf","name":"http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"application/pdf","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4175","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4175","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4175","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"insyde","cpe5":"insyde_bios","cpe6":"v190","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:38:51.321Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.ivizsecurity.com/preboot-patch.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"},{"name":"15751","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15751"},{"name":"20051213 Bios Information Leakage","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/419610/100/0/threaded"},{"name":"VU#847537","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/847537"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.ivizsecurity.com/preboot-patch.html"},{"tags":["x_refsource_MISC"],"url":"http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"},{"name":"15751","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15751"},{"name":"20051213 Bios Information Leakage","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/419610/100/0/threaded"},{"name":"VU#847537","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/847537"},{"tags":["x_refsource_MISC"],"url":"http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4175","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.ivizsecurity.com/preboot-patch.html","refsource":"MISC","url":"http://www.ivizsecurity.com/preboot-patch.html"},{"name":"http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf","refsource":"MISC","url":"http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"},{"name":"15751","refsource":"BID","url":"http://www.securityfocus.com/bid/15751"},{"name":"20051213 Bios Information Leakage","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/419610/100/0/threaded"},{"name":"VU#847537","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/847537"},{"name":"http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt","refsource":"MISC","url":"http://www.pulltheplug.org/users/endrazine/Bios.Information.Leakage.txt"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4175","datePublished":"2005-12-11T21:00:00.000Z","dateReserved":"2005-12-11T00:00:00.000Z","dateUpdated":"2024-08-07T23:38:51.321Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-11 21:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:insyde:insyde_bios:v190:*:*:*:*:*:*:*","matchCriteriaId":"12B464EA-B99F-4E76-97F6-9CD16B6F06D7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4175","Ordinal":"1","Title":"CVE-2005-4175","CVE":"CVE-2005-4175","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4175","Ordinal":"1","NoteData":"Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.","Type":"Description","Title":"CVE-2005-4175"},{"CveYear":"2005","CveId":"4175","Ordinal":"2","NoteData":"2005-12-11","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4175","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}