J-Security Center

Title: Palm Debugger Password Bypass Vulnerability

Severity: MODERATE

Description:

The Palm OS provides password protection, allowing the device's owner to restrict access to sensitive data by requiring the entry of a password upon startup of the unit.

Two distinct, inbuilt Palm OS debugging modes are accessible from the Graffiti stylus interface. These allow any user with physical access to the PDA to bypass the unit's password lockout and read or change sensitive data.

The "debugger mode" and "console mode" backdoors, documented features of all versions of the OS, allow source- and machine-code-level debugging of programs on the Palm, as well as manipulation of records and system password information. Other supported functions permit formatting of memory cards, display of memory contents and replacing records in a Palm database.

Affected Products:

  • Palm Palm OS 3.3.0
  • Palm Palm OS 3.5.2

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.