CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:N/I:C/A:C
EPSS
Percentile
26.7%
pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a
smart card unless the cardโs label matches the โOpenSCโ string, which might
allow physically proximate attackers to exploit vulnerabilities that the
card owner expected were patched, as demonstrated by exploitation of
CVE-2008-2235.