- Description
- Datakey Rainbow iKey2032 USB token, when using the CIP client package, does not encrypt communications between the token and the driver, which could allow local users to obtain the PINs of other users.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:N/A:N
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:datakey:rainbow_ikey2032_usb_token:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "71AF16D7-9F34-4BBA-BA99-3A14D94F0529"
}
],
"operator": "OR"
}
]
}
]