Intel D845 Motherboard BIOS Series Arbitrary Boot Media Vulnerability

BID:4610

Info

Intel D845 Motherboard BIOS Series Arbitrary Boot Media Vulnerability

Bugtraq ID: 4610
Class: Configuration Error
CVE:
Remote: No
Local: Yes
Published: Apr 26 2002 12:00AM
Updated: Apr 26 2002 12:00AM
Credit: Vulnerability discovery credited to Dave Oliver <[email protected]>.
Vulnerable: Intel Corporation D845WN Motherboard P11-0040
Intel Corporation D845WN Motherboard P10-0038
Intel Corporation D845WN Motherboard P09-0035
Intel Corporation D845WN Motherboard P08-0031
Intel Corporation D845WN Motherboard P07-0029
Intel Corporation D845WN Motherboard P06-0024
Intel Corporation D845WN Motherboard P05-0022
Intel Corporation D845WN Motherboard P04-0018
Intel Corporation D845PT Motherboard P05-0024
Intel Corporation D845PT Motherboard P04-0023
Intel Corporation D845PT Motherboard P03-0021
Intel Corporation D845PT Motherboard P02-0015
Intel Corporation D845PT Motherboard P01-0012
Intel Corporation D845HV Motherboard P11-0040
Intel Corporation D845HV Motherboard P10-0038
Intel Corporation D845HV Motherboard P09-0035
Intel Corporation D845HV Motherboard P08-0031
Intel Corporation D845HV Motherboard P07-0029
Intel Corporation D845HV Motherboard P06-0024
Intel Corporation D845HV Motherboard P05-0022
Intel Corporation D845HV Motherboard P04-0018
Intel Corporation D845BG Motherboard P05-0024
Intel Corporation D845BG Motherboard P04-0023
Intel Corporation D845BG Motherboard P03-0021
Intel Corporation D845BG Motherboard P02-0015
Intel Corporation D845BG Motherboard P01-0012
Not Vulnerable:

Discussion

Intel D845 Motherboard BIOS Series Arbitrary Boot Media Vulnerability

The D845 series motherboards are a product of Intel. These motherboards are designed to support the Pentium 4 processor.

When a system using a D845 series motherboard is booted, it is possible to halt the boot to change the boot media, even if a BIOS password is set. By pressing the F8 key, the D845 BIOS will give a user at the console a menu. From this menu, a user may specify a different media than the default from which the system is to be booted. Any password set on the BIOS will be circumvented by this procedure.

Exploit / POC

Intel D845 Motherboard BIOS Series Arbitrary Boot Media Vulnerability

This vulnerability requires no exploit.

Solution / Fix

Intel D845 Motherboard BIOS Series Arbitrary Boot Media Vulnerability

Solution:
Vendor fixes available:


Intel Corporation D845BG Motherboard P03-0021

Intel Corporation D845WN Motherboard P05-0022

Intel Corporation D845BG Motherboard P05-0024

Intel Corporation D845HV Motherboard P11-0040

Intel Corporation D845PT Motherboard P03-0021

Intel Corporation D845WN Motherboard P11-0040

Intel Corporation D845HV Motherboard P04-0018

Intel Corporation D845PT Motherboard P01-0012

Intel Corporation D845WN Motherboard P04-0018

Intel Corporation D845BG Motherboard P01-0012

Intel Corporation D845WN Motherboard P06-0024

Intel Corporation D845HV Motherboard P05-0022

Intel Corporation D845BG Motherboard P02-0015

Intel Corporation D845HV Motherboard P06-0024

Intel Corporation D845HV Motherboard P08-0031

Intel Corporation D845PT Motherboard P02-0015

Intel Corporation D845BG Motherboard P04-0023

Intel Corporation D845WN Motherboard P10-0038

Intel Corporation D845PT Motherboard P04-0023

Intel Corporation D845HV Motherboard P09-0035

Intel Corporation D845HV Motherboard P07-0029

Intel Corporation D845WN Motherboard P08-0031

Intel Corporation D845HV Motherboard P10-0038

Intel Corporation D845WN Motherboard P07-0029

Intel Corporation D845WN Motherboard P09-0035

Intel Corporation D845PT Motherboard P05-0024

References

Intel D845 Motherboard BIOS Series Arbitrary Boot Media Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report