Back

MEDIUM

opensc: incorrect initialization of Siemens CardOS M4 smart cards

Published Aug 1, 2008

Description

OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 1, 2008
Updated Aug 7, 2024
Reserved May 16, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Jul 31, 2008