LOW · 2.1

CVE-2009-0368

OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by ...

Vulnerability Description

OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Opensc-ProjectOpensc<= 0.11.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-0368?

CVE-2009-0368 is a vulnerability with a CVSS score of 2.1 (LOW). OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by ...

How severe is CVE-2009-0368?

CVE-2009-0368 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0368?

Check the references section above for vendor advisories and patch information. Affected products include: Opensc-Project Opensc.