An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.
CVSS Details
- CVSS 3.1 Base Score: 4.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade opensc | Dec 27, 2023 | Nov 6, 2023 |
| Alpine Linux | — | Upgrade opensc | Aug 22, 2024 | Nov 6, 2023 |
| Amazon_linux_2023 | — | Upgrade opensc-debugsourceUpgrade openscUpgrade opensc-debuginfo | Feb 17, 2025 | Sep 25, 2023 |
| Centos_linux | — | Upgrade opensc-debuginfoUpgrade opensc-debugsourceUpgrade opensc | Dec 20, 2023 | Nov 6, 2023 |
| Debian | — | Upgrade opensc | Jul 30, 2024 | Nov 6, 2023 |
| Gentoo Linux | — | Upgrade dev-libs/opensc. | Dec 12, 2024 | Nov 6, 2023 |
| Oracle_linux | — | Upgrade opensc | Dec 19, 2023 | Sep 25, 2023 |
| Redhat_linux | — | Upgrade openscUpgrade opensc-debuginfoUpgrade opensc-debugsource | Dec 20, 2023 | Nov 6, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub