In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered by a smartcard before login), allowing authentication bypass.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pam-pkcs11 | Feb 14, 2025 | Feb 14, 2025 |
| Suse | — | Upgrade pam_pkcs11-devel-docUpgrade pam_pkcs11 | Dec 5, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade libpam-pkcs11 (Ubuntu Pro)Upgrade libpam-pkcs11 | Mar 21, 2025 | Feb 7, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub