{"api_version":"1","generated_at":"2026-07-23T08:04:36+00:00","cve":"CVE-2008-3898","urls":{"html":"https://cve.report/CVE-2008-3898","api":"https://cve.report/api/cve/CVE-2008-3898.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3898","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3898"},"summary":{"title":"CVE-2008-3898","description":"Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-09-03 14:12:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.ivizsecurity.com/preboot-patch.html","name":"http://www.ivizsecurity.com/preboot-patch.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"iViZ - On Demand Automated Penetration Testing","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4213","name":"http://securityreason.com/securityalert/4213","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason - DriveCrypt Security Model bypass exploiting wrong BIOS API usage","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31605","name":"http://secunia.com/advisories/31605","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"DriveCrypt Plus Pack Password Disclosure Security Issue - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/30818","name":"http://www.securityfocus.com/bid/30818","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Retired: DriveCrypt Incorrect BIOS API Usage Security Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf","name":"http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"application/pdf","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.ivizsecurity.com/security-advisory-iviz-sr-0807.html","name":"http://www.ivizsecurity.com/security-advisory-iviz-sr-0807.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"iViZ - On Demand Automated Penetration Testing","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/495803/100/0/threaded","name":"http://www.securityfocus.com/archive/1/495803/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3898","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3898","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3898","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"secustar","cpe5":"drivecrypt_plus_pack","cpe6":"3.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:53:00.652Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"31605","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31605"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.ivizsecurity.com/security-advisory-iviz-sr-0807.html"},{"name":"30818","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30818"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.ivizsecurity.com/preboot-patch.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"},{"name":"20080825 [IVIZ-08-007] DriveCrypt Security Model bypass exploiting wrong BIOS API usage","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/495803/100/0/threaded"},{"name":"4213","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4213"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-08-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"31605","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31605"},{"tags":["x_refsource_MISC"],"url":"http://www.ivizsecurity.com/security-advisory-iviz-sr-0807.html"},{"name":"30818","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30818"},{"tags":["x_refsource_MISC"],"url":"http://www.ivizsecurity.com/preboot-patch.html"},{"tags":["x_refsource_MISC"],"url":"http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"},{"name":"20080825 [IVIZ-08-007] DriveCrypt Security Model bypass exploiting wrong BIOS API usage","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/495803/100/0/threaded"},{"name":"4213","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4213"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3898","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"31605","refsource":"SECUNIA","url":"http://secunia.com/advisories/31605"},{"name":"http://www.ivizsecurity.com/security-advisory-iviz-sr-0807.html","refsource":"MISC","url":"http://www.ivizsecurity.com/security-advisory-iviz-sr-0807.html"},{"name":"30818","refsource":"BID","url":"http://www.securityfocus.com/bid/30818"},{"name":"http://www.ivizsecurity.com/preboot-patch.html","refsource":"MISC","url":"http://www.ivizsecurity.com/preboot-patch.html"},{"name":"http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf","refsource":"MISC","url":"http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"},{"name":"20080825 [IVIZ-08-007] DriveCrypt Security Model bypass exploiting wrong BIOS API usage","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/495803/100/0/threaded"},{"name":"4213","refsource":"SREASON","url":"http://securityreason.com/securityalert/4213"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3898","datePublished":"2008-09-03T14:00:00.000Z","dateReserved":"2008-09-03T00:00:00.000Z","dateUpdated":"2024-08-07T09:53:00.652Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-09-03 14:12:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:secustar:drivecrypt_plus_pack:3.9:*:*:*:*:*:*:*","matchCriteriaId":"03119419-5631-4E22-8521-BEC78D62EE3E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3898","Ordinal":"1","Title":"CVE-2008-3898","CVE":"CVE-2008-3898","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3898","Ordinal":"1","NoteData":"Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.","Type":"Description","Title":"CVE-2008-3898"},{"CveYear":"2008","CveId":"3898","Ordinal":"2","NoteData":"2008-09-03","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3898","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}