4.9
CVE-2008-2235
- EPSS 0.07%
- Veröffentlicht 01.08.2008 14:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opensc-project ≫ Opensc Version0.3.2
Opensc-project ≫ Opensc Version0.3.5
Opensc-project ≫ Opensc Version0.4.0
Opensc-project ≫ Opensc Version0.6.0
Opensc-project ≫ Opensc Version0.6.1
Opensc-project ≫ Opensc Version0.7.0
Opensc-project ≫ Opensc Version0.8
Opensc-project ≫ Opensc Version0.8.0.0
Opensc-project ≫ Opensc Version0.8.1
Opensc-project ≫ Opensc Version0.9
Opensc-project ≫ Opensc Version0.9.6
Opensc-project ≫ Opensc Version0.9.7
Opensc-project ≫ Opensc Version0.9.7 Updateb
Opensc-project ≫ Opensc Version0.9.7 Updated
Opensc-project ≫ Opensc Version0.9.8
Opensc-project ≫ Opensc Version0.11.0
Opensc-project ≫ Opensc Version0.11.1
Opensc-project ≫ Opensc Version0.11.2
Opensc-project ≫ Opensc Version0.11.3
Opensc-project ≫ Opensc Version0.11.3 Updatepre3
Opensc-project ≫ Opensc Version0.11.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.177 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:N/I:C/A:N
|