https://seclists.org/oss-sec/2023/q4/271: CVE-2023-40660: Potential PIN bypass with empty PIN in OpenSC before 0.24.0
Published Dec 13, 2023
·Updated
Affected Software
1 affected component
OpenSC OpenSC<0.24.0
Frequently Asked Questions
1
What is the severity of CVE-2023-40660?
CVE-2023-40660 is considered a high-severity vulnerability due to the potential for unauthorized cryptographic operations.
2
How do I fix CVE-2023-40660?
To fix CVE-2023-40660, upgrade OpenSC to version 0.24.0 or later, where the vulnerability is addressed.
3
What systems are affected by CVE-2023-40660?
CVE-2023-40660 affects versions of OpenSC prior to 0.24.0.
4
What are the risks associated with CVE-2023-40660?
The risks include unauthorized access and cryptographic operations due to the ability to bypass PIN authentication with an empty PIN.
5
How can I verify if CVE-2023-40660 is mitigated in my implementation?
You can verify mitigation by checking your OpenSC version and ensuring it is updated to 0.24.0 or later.