CVE-2008-3896 describes a vulnerability in Grub Legacy 0.97 and earlier where pre-boot authentication passwords are left in the BIOS Keyboard buffer, allowing local users to read physical memory and retrieve sensitive information. This vulnerability has a low severity CVSS score of 2.1, indicating a low attack complexity and requiring local access to compromise confidentiality. There is no evidence of active exploitation, nor are there known public exploits or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.97CPE matchmatch criteria | cpe:2.3:a:gnu:grub_legacy:*:*:*:*:*:*:*:* | ||
0.92CPE matchmatch criteria | cpe:2.3:a:gnu:grub_legacy:0.92:*:*:*:*:*:*:* | ||
0.93CPE matchmatch criteria | cpe:2.3:a:gnu:grub_legacy:0.93:*:*:*:*:*:*:* | ||
0.94CPE matchmatch criteria | cpe:2.3:a:gnu:grub_legacy:0.94:*:*:*:*:*:*:* | ||
0.94-i386-pcCPE matchmatch criteria | cpe:2.3:a:gnu:grub_legacy:0.94-i386-pc:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.