First published: Fri Aug 01 2008(Updated: )
OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/opensc | 0.19.0-1+deb10u1 0.19.0-1+deb10u2 0.21.0-1 0.23.0-0.3 0.23.0-1 | |
Siemens CardOS | =m4 | |
SUSE OpenSC | =0.3.2 | |
SUSE OpenSC | =0.3.5 | |
SUSE OpenSC | =0.4.0 | |
SUSE OpenSC | =0.6.0 | |
SUSE OpenSC | =0.6.1 | |
SUSE OpenSC | =0.7.0 | |
SUSE OpenSC | =0.8 | |
SUSE OpenSC | =0.8.0.0 | |
SUSE OpenSC | =0.8.1 | |
SUSE OpenSC | =0.9 | |
SUSE OpenSC | =0.9.6 | |
SUSE OpenSC | =0.9.7 | |
SUSE OpenSC | =0.9.7-b | |
SUSE OpenSC | =0.9.7-d | |
SUSE OpenSC | =0.9.8 | |
SUSE OpenSC | =0.11.0 | |
SUSE OpenSC | =0.11.1 | |
SUSE OpenSC | =0.11.2 | |
SUSE OpenSC | =0.11.3 | |
SUSE OpenSC | =0.11.3-pre3 | |
SUSE OpenSC | =0.11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2235 is classified as a medium severity vulnerability due to the potential for physical access attacks.
To fix CVE-2008-2235, upgrade OpenSC to version 0.11.5 or later.
CVE-2008-2235 affects smart cards and USB crypto tokens using Siemens CardOS M4 and older versions of OpenSC.
The impact of CVE-2008-2235 is that it allows physically proximate attackers to change the PIN of affected smart cards.
CVE-2008-2235 is not a concern for versions of OpenSC newer than 0.11.5, as the vulnerability has been addressed.