CVE-2023-4535

Published Nov 6, 2023

Last updated 2 months ago

Overview

Description
An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.
Source
secalert@redhat.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
3.8
Impact score
3.4
Exploitability score
0.4
Vector string
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Severity
LOW

Weaknesses

nvd@nist.gov
CWE-125
secalert@redhat.com
CWE-125

Social media

Hype score
Not currently trending

Configurations