Lucene search

K
cveMitreCVE-2004-0063
HistorySep 01, 2004 - 4:00 a.m.

CVE-2004-0063

2004-09-0104:00:00
mitre
web.nvd.nist.gov
26
cve
ncipher payshield
spp library
security vulnerability
pin number
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.005

Percentile

76.1%

The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.

Affected configurations

Nvd
Node
ncipherpayshield_spp_libraryMatch1.3.12
OR
ncipherpayshield_spp_libraryMatch1.5.18
OR
ncipherpayshield_spp_libraryMatch1.6.18
VendorProductVersionCPE
ncipherpayshield_spp_library1.3.12cpe:2.3:a:ncipher:payshield_spp_library:1.3.12:*:*:*:*:*:*:*
ncipherpayshield_spp_library1.5.18cpe:2.3:a:ncipher:payshield_spp_library:1.5.18:*:*:*:*:*:*:*
ncipherpayshield_spp_library1.6.18cpe:2.3:a:ncipher:payshield_spp_library:1.6.18:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.005

Percentile

76.1%

Related for CVE-2004-0063