CVE-2025-49010 is a stack-buffer-overflow vulnerability found in OpenSC versions prior to 0.27.0, specifically within its GET RESPONSE function. This medium-severity vulnerability (CVSS 6.8) requires an attacker to have physical access to the system and present a specially crafted USB device or smart card while a user or administrator is actively using a token. Successful exploitation could lead to high impact on confidentiality, integrity, and availability. However, it relies on specific timing and physical presence, making the attack vector physical (AV:P) and attack complexity low (AC:L). There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.27.0CPE matchmatch criteria | cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.