4.9
CVSSv2

CVE-2008-2235

Published: 01/08/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:C/A:N

Vulnerability Summary

OpenSC prior to 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate malicious users to change the PIN.

Vulnerable Product Search on Vulmon Subscribe to Product

opensc-project opensc 0.11.2

opensc-project opensc 0.11.3

opensc-project opensc 0.7.0

opensc-project opensc 0.8

opensc-project opensc 0.9.7

opensc-project opensc 0.9.8

opensc-project opensc 0.11.4

opensc-project opensc 0.8.0.0

opensc-project opensc 0.8.1

opensc-project opensc 0.3.2

opensc-project opensc 0.3.5

opensc-project opensc 0.9

opensc-project opensc 0.9.6

opensc-project opensc 0.11.0

opensc-project opensc 0.11.1

opensc-project opensc 0.4.0

opensc-project opensc 0.6.0

opensc-project opensc 0.6.1

Vendor Advisories

Chaskiel M Grundman discovered that opensc, a library and utilities to handle smart cards, would initialise smart cards with the Siemens CardOS M4 card operating system without proper access rights This allowed everyone to change the card's PIN With this bug anyone can change a user PIN without having the PIN or PUK or the superusers PIN or PUK ...