CVE-2008-2235
published 2008-08-01CVE-2008-2235: OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens…
PriorityP415medium4.9CVSS 2.0
AVLACLAuNCNICAN
EPSS
0.39%
31.9th percentile
OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cobbler_project | cobbler | >= 0 < 2.0.7 | 2.0.7 |
| debian | opensc | < opensc 0.11.4-5 (bookworm) | opensc 0.11.4-5 (bookworm) |
| debian | opensc | < opensc 0.11.4-4 (bookworm) | opensc 0.11.4-4 (bookworm) |
| opensc-project | opensc | <= 0.11.5 | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:C/A:N
ghsa9.0CRITICAL
osv4.9MEDIUM
vendor_redhat9.0CRITICAL
vendor_debian4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
(cobbler): Code injection flaw (ACE as root) by processing of a specially-crafted kickstart template file
vendor_redhat·2010-10-18·CVSS 9.0
CVE-2010-2235 [CRITICAL] CWE-96 (cobbler): Code injection flaw (ACE as root) by processing of a specially-crafted kickstart template file
(cobbler): Code injection flaw (ACE as root) by processing of a specially-crafted kickstart template file
template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.
Red Hat
opensc: incorrect initialization of Siemens CardOS M4 smart cards
vendor_redhat·2008-07-31·CVSS 4.9
CVE-2008-2235 [MEDIUM] opensc: incorrect initialization of Siemens CardOS M4 smart cards
opensc: incorrect initialization of Siemens CardOS M4 smart cards
OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.
Debian
CVE-2008-3972: opensc - pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart c...
vendor_debian·2008·CVSS 4.9
CVE-2008-3972 [MEDIUM] CVE-2008-3972: opensc - pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart c...
pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.
Scope: local
bookworm: resolved (fixed in 0.11.4-5)
bullseye: resolved (fixed in 0.11.4-5)
forky: resolved (fixed in 0.11.4-5)
sid: resolved (fixed in 0.11.4-5)
trixie: resolved (fixed in 0.11.4-5)
Debian
CVE-2008-2235: opensc - OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00...
vendor_debian·2008·CVSS 4.9
CVE-2008-2235 [MEDIUM] CVE-2008-2235: opensc - OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00...
OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.
Scope: local
bookworm: resolved (fixed in 0.11.4-4)
bullseye: resolved (fixed in 0.11.4-4)
forky: resolved (fixed in 0.11.4-4)
sid: resolved (fixed in 0.11.4-4)
trixie: resolved (fixed in 0.11.4-4)
GHSA
Cobbler is vulnerable to code injection
ghsa·2022-05-17·CVSS 9.0
CVE-2010-2235 [CRITICAL] CWE-94 Cobbler is vulnerable to code injection
Cobbler is vulnerable to code injection
template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.
GHSA
GHSA-445p-3crg-24jx: pkcs15-tool in OpenSC before 0
ghsa_unreviewed·2022-05-02·CVSS 4.9
CVE-2008-3972 [MEDIUM] GHSA-445p-3crg-24jx: pkcs15-tool in OpenSC before 0
pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.
GHSA
GHSA-8cph-r8x9-fxx9: OpenSC before 0
ghsa_unreviewed·2022-05-01
CVE-2008-2235 [MEDIUM] GHSA-8cph-r8x9-fxx9: OpenSC before 0
OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.
OSV
CVE-2008-3972: pkcs15-tool in OpenSC before 0
osv·2008-09-11·CVSS 4.9
CVE-2008-3972 [MEDIUM] CVE-2008-3972: pkcs15-tool in OpenSC before 0
pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.
OSV
CVE-2008-2235: OpenSC before 0
osv·2008-08-01·CVSS 4.9
CVE-2008-2235 [MEDIUM] CVE-2008-2235: OpenSC before 0
OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.htmlhttp://secunia.com/advisories/31330http://secunia.com/advisories/31360http://secunia.com/advisories/32099http://secunia.com/advisories/33115http://secunia.com/advisories/34362http://security.gentoo.org/glsa/glsa-200812-09.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:183http://www.opensc-project.org/pipermail/opensc-announce/2008-July/000020.htmlhttp://www.opensc-project.org/security.htmlhttp://www.securityfocus.com/bid/30473https://exchange.xforce.ibmcloud.com/vulnerabilities/44140https://www.debian.org/security/2008/dsa-1627https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00686.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.htmlhttp://secunia.com/advisories/31330http://secunia.com/advisories/31360http://secunia.com/advisories/32099http://secunia.com/advisories/33115http://secunia.com/advisories/34362http://security.gentoo.org/glsa/glsa-200812-09.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:183http://www.opensc-project.org/pipermail/opensc-announce/2008-July/000020.htmlhttp://www.opensc-project.org/security.htmlhttp://www.securityfocus.com/bid/30473https://exchange.xforce.ibmcloud.com/vulnerabilities/44140https://www.debian.org/security/2008/dsa-1627https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00686.html
2008-08-01
Published