Vulnerability Details CVE-2008-3972
pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.1%
CVSS Severity
CVSS v2 Score 6.6
Products affected by CVE-2008-3972
-
cpe:2.3:a:opensc-project:opensc:*
-
cpe:2.3:a:opensc-project:opensc:0.10.0
-
cpe:2.3:a:opensc-project:opensc:0.10.1
-
cpe:2.3:a:opensc-project:opensc:0.11.0
-
cpe:2.3:a:opensc-project:opensc:0.11.1
-
cpe:2.3:a:opensc-project:opensc:0.11.2
-
cpe:2.3:a:opensc-project:opensc:0.11.3
-
cpe:2.3:a:opensc-project:opensc:0.11.4
-
cpe:2.3:a:opensc-project:opensc:0.4.0
-
cpe:2.3:a:opensc-project:opensc:0.5.0
-
cpe:2.3:a:opensc-project:opensc:0.6.0
-
cpe:2.3:a:opensc-project:opensc:0.6.1
-
cpe:2.3:a:opensc-project:opensc:0.7.0
-
cpe:2.3:a:opensc-project:opensc:0.8.0
-
cpe:2.3:a:opensc-project:opensc:0.8.1
-
cpe:2.3:a:opensc-project:opensc:0.9.2
-
cpe:2.3:a:opensc-project:opensc:0.9.3
-
cpe:2.3:a:opensc-project:opensc:0.9.4
-
cpe:2.3:a:opensc-project:opensc:0.9.5
-
cpe:2.3:a:opensc-project:opensc:0.9.6
-
cpe:2.3:o:siemens:cardos:m4