An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.
CVSS Details
- CVSS 3.1 Base Score: 4.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-opensc | Dec 27, 2023 | Nov 6, 2023 | |
| Alpine Linux | alpine-linux-upgrade-opensc | Aug 22, 2024 | Nov 6, 2023 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-openscamazon-linux-2023-upgrade-opensc-debuginfoamazon-linux-2023-upgrade-opensc-debugsource | Feb 17, 2025 | Sep 25, 2023 | |
| Centos_linux | — | centos-upgrade-opensccentos-upgrade-opensc-debuginfocentos-upgrade-opensc-debugsource | Dec 20, 2023 | Nov 6, 2023 |
| Debian | debian-upgrade-opensc | Jul 30, 2024 | Nov 6, 2023 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-libs-opensc | Dec 12, 2024 | Nov 6, 2023 | |
| Oracle_linux | — | oracle-linux-upgrade-opensc | Dec 19, 2023 | Sep 25, 2023 |
| Redhat_linux | redhat-upgrade-openscredhat-upgrade-opensc-debuginforedhat-upgrade-opensc-debugsource | Dec 20, 2023 | Nov 6, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub