CVE-2008-3972

CVSS 6.6 - MEDIUM
Description

pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.

Affected Products
22
Vendor Product Version
opensc-project opensc All versions
opensc-project opensc 0.4.0
opensc-project opensc 0.5.0
opensc-project opensc 0.6.0
opensc-project opensc 0.6.1
opensc-project opensc 0.7.0
opensc-project opensc 0.8.0
opensc-project opensc 0.8.1
opensc-project opensc 0.9.2
opensc-project opensc 0.9.3
opensc-project opensc 0.9.4
opensc-project opensc 0.9.5
opensc-project opensc 0.9.6
opensc-project opensc 0.10.0
opensc-project opensc 0.10.1
opensc-project opensc 0.11.0
opensc-project opensc 0.11.1
opensc-project opensc 0.11.2
opensc-project opensc 0.11.3
opensc-project opensc 0.11.3
opensc-project opensc 0.11.4
siemens cardos m4
Weakness Types
CWE-264
CVE Information
CVE ID:
CVE-2008-3972
Published:
2008-09-11
Modified:
2026-04-23
CVSS Score:
6.6
Severity:
MEDIUM
Vector:
AV:L/AC:L/Au:N/C:N/I:C/A:C
Affected Vendors
opensc-project siemens
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL