4.9

CVE-2008-2235

OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.

Data is provided by the National Vulnerability Database (NVD)
Opensc-projectOpensc Version0.3.2
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.3.5
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.4.0
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.6.0
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.6.1
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.7.0
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.8
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.8.0.0
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.8.1
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.9
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.9.6
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.9.7
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.9.7 Updateb
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.9.7 Updated
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.9.8
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.11.0
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.11.1
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.11.2
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.11.3
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.11.3 Updatepre3
   SiemensCardos Versionm4
Opensc-projectOpensc Version0.11.4
   SiemensCardos Versionm4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.177
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:C/A:N