ECS K7S5A Boot Menu Access Vulnerability
BID:4866
Info
ECS K7S5A Boot Menu Access Vulnerability
| Bugtraq ID: | 4866 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 28 2002 12:00AM |
| Updated: | May 28 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Guy Van Sanden <[email protected]>. |
| Vulnerable: |
ECS K7S5A(L) V.02/02/06 |
| Not Vulnerable: | |
Discussion
ECS K7S5A Boot Menu Access Vulnerability
K7S5A is a line of mainboards manufactured and distributed by ECS.
The firmware distributed with K7S5A boards may allow users with physical access to systems to boot of alternative media. Though the firmware allows the setting of administrative passwords and specification of default boot media, it does not protect the boot menu. With access to the boot menu, arbitrary media such as a floppy or CD may be booted from.
K7S5A is a line of mainboards manufactured and distributed by ECS.
The firmware distributed with K7S5A boards may allow users with physical access to systems to boot of alternative media. Though the firmware allows the setting of administrative passwords and specification of default boot media, it does not protect the boot menu. With access to the boot menu, arbitrary media such as a floppy or CD may be booted from.
Exploit / POC
ECS K7S5A Boot Menu Access Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
ECS K7S5A Boot Menu Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.