← Back

CVE-2008-2235

nvd nist
Published: Aug 1, 2008Modified: Apr 23, 2026

JSON object

Loading...
4.9
Vector
AV:L/AC:L/Au:N/C:N/I:C/A:N
Exploitability: 3.9 / Impact: 6.9
Source: NVD

Description

OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.

Affected (21)

Opensc
Configuration A
21 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Opensc Project
Version 0.11.0
Version 0.11.1
Version 0.11.2
Version 0.11.3
Version 0.11.3 pre3
Version 0.11.4
Version 0.3.2
Version 0.3.5
Version 0.4.0
Version 0.6.0
Version 0.6.1
Version 0.7.0
Version 0.8.0.0
Version 0.8.1
Version 0.8
Version 0.9.6
Version 0.9.7
Version 0.9.7 b
Version 0.9.7 d
Version 0.9.8
Version 0.9
Running on/withPlatform Versions
Siemens
Cardos
Version m4

Related CWEs

References (30)

Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.