MEDIUM · 4.9

CVE-2008-2235

OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proxima...

Vulnerability Description

OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.

CVSS Score

4.9

MEDIUM

AV:L/AC:L/Au:N/C:N/I:C/A:N
Confidentiality
NONE
Integrity
COMPLETE
Availability
NONE

Affected Products

VendorProductVersions
SiemensCardosm4
Opensc-ProjectOpensc0.3.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-2235?

CVE-2008-2235 is a vulnerability with a CVSS score of 4.9 (MEDIUM). OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proxima...

How severe is CVE-2008-2235?

CVE-2008-2235 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-2235?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Cardos, Opensc-Project Opensc.