MEDIUM · 4.5

CVE-2023-4535

An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to th...

Vulnerability Description

An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.

CVSS Score

4.5

MEDIUM

CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
Opensc ProjectOpensc0.23.0
FedoraprojectFedora38
RedhatEnterprise Linux9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-4535?

CVE-2023-4535 is a vulnerability with a CVSS score of 4.5 (MEDIUM). An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to th...

How severe is CVE-2023-4535?

CVE-2023-4535 has been rated MEDIUM with a CVSS base score of 4.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-4535?

Check the references section above for vendor advisories and patch information. Affected products include: Opensc Project Opensc, Fedoraproject Fedora, Redhat Enterprise Linux.