CVE-2008-2235 describes a vulnerability in OpenSC versions prior to 0.11.5, affecting smart cards and USB crypto tokens running Siemens CardOS M4. The vulnerability stems from weak permissions (ADMIN file control information of 00) on the 5015 directory, allowing physically proximate attackers to alter the PIN. This is a low-severity vulnerability (CVSS 4.9) with a local attack vector and low attack complexity, resulting in a potential impact of unauthorized PIN changes. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.3.2CPE matchmatch criteria | cpe:2.3:a:opensc-project:opensc:0.3.2:*:*:*:*:*:*:* | ||
0.3.5CPE matchmatch criteria | cpe:2.3:a:opensc-project:opensc:0.3.5:*:*:*:*:*:*:* | ||
0.4.0CPE matchmatch criteria | cpe:2.3:a:opensc-project:opensc:0.4.0:*:*:*:*:*:*:* | ||
0.6.0CPE matchmatch criteria | cpe:2.3:a:opensc-project:opensc:0.6.0:*:*:*:*:*:*:* | ||
0.6.1CPE matchmatch criteria | cpe:2.3:a:opensc-project:opensc:0.6.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:C/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.