Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-phh2-j3h6-vqr9

Опубликовано: 06 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.5

Описание

An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.

An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.

EPSS

Процентиль: 42%
0.00199
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 4.5
ubuntu
больше 1 года назад

An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.

CVSS3: 4.5
redhat
почти 2 года назад

An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.

CVSS3: 4.5
nvd
больше 1 года назад

An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.

CVSS3: 3.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 4.5
debian
больше 1 года назад

An out-of-bounds read vulnerability was found in OpenSC packages withi ...

EPSS

Процентиль: 42%
0.00199
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-125