4.9
CVE-2008-2235
- EPSS 0.07%
- Published 01.08.2008 14:41:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.
Data is provided by the National Vulnerability Database (NVD)
Opensc-project ≫ Opensc Version0.3.2
Opensc-project ≫ Opensc Version0.3.5
Opensc-project ≫ Opensc Version0.4.0
Opensc-project ≫ Opensc Version0.6.0
Opensc-project ≫ Opensc Version0.6.1
Opensc-project ≫ Opensc Version0.7.0
Opensc-project ≫ Opensc Version0.8
Opensc-project ≫ Opensc Version0.8.0.0
Opensc-project ≫ Opensc Version0.8.1
Opensc-project ≫ Opensc Version0.9
Opensc-project ≫ Opensc Version0.9.6
Opensc-project ≫ Opensc Version0.9.7
Opensc-project ≫ Opensc Version0.9.7 Updateb
Opensc-project ≫ Opensc Version0.9.7 Updated
Opensc-project ≫ Opensc Version0.9.8
Opensc-project ≫ Opensc Version0.11.0
Opensc-project ≫ Opensc Version0.11.1
Opensc-project ≫ Opensc Version0.11.2
Opensc-project ≫ Opensc Version0.11.3
Opensc-project ≫ Opensc Version0.11.3 Updatepre3
Opensc-project ≫ Opensc Version0.11.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.177 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:N/I:C/A:N
|