pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.
CVSS Details
- CVSS 3.1 Base Score: 7.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opensc | Jul 30, 2024 | Sep 11, 2008 |
| Suse | — | Upgrade opensc-64bitUpgrade libopensc2-32bitUpgrade openscUpgrade libopensc2-64bitUpgrade suse-releaseUpgrade opensc-32bitUpgrade libopensc2Upgrade opensc-devel | Feb 17, 2015 | Sep 10, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub