Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

OpenSC CardOS M4 Smart Cards Insecure Permissions Vulnerability

OpenSC insecurely initializes smart cards and USB crypto tokens based on Seimens CardOS M4.

Attackers can leverage this issue to change the PIN number on a card without having knowledge of the existing PIN or PUK number. Successfully exploiting this issue allows attackers to use the card in further attacks.

NOTE: This issue cannot be leveraged to access an existing PIN number.

This issue occurs in versions prior to OpenSC 0.11.6.







 

Privacy Statement
Copyright 2008, SecurityFocus