CVE-2023-4535 is an out-of-bounds read vulnerability in the MyEID driver within OpenSC packages, affecting various Fedora and Red Hat Enterprise Linux versions. This low-severity flaw requires physical access to the system and a specially crafted USB device or smart card to exploit, allowing an attacker to manipulate APDU responses and potentially gain limited access to sensitive data. While the vulnerability has a low CVSS score of 3.8, its potential impact includes compromise of confidentiality, integrity, and availability. There is no known active exploitation, public exploit code, or significant community discussion, and it is not listed in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.23.0CPE matchmatch criteria | cpe:2.3:a:opensc_project:opensc:0.23.0:-:*:*:*:*:*:* | ||
0.23.0CPE matchmatch criteria | cpe:2.3:a:opensc_project:opensc:0.23.0:rc1:*:*:*:*:*:* | ||
0.23.0CPE matchmatch criteria | cpe:2.3:a:opensc_project:opensc:0.23.0:rc2:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-4535
Jun 11, 2024Opensc: out-of-bounds read in myeid driver handling encryption using symmetric keys
Nov 14, 2023OpenSC: out-of-bounds read in MyEID driver handling encryption using symmetric keys
Sep 25, 2023