CVE-2023-40660
Summary
| CVE | CVE-2023-40660 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-06 17:15:00 UTC |
| Updated | 2023-11-14 17:12:00 UTC |
| Description | A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS logon/screen unlock and for small, permanently connected tokens to computers. Additionally, the token can internally track login status. This flaw allows an attacker to gain unauthorized access, carry out malicious actions, or compromise the system without the user's awareness. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| OpenSC security advisories · OpenSC/OpenSC Wiki · GitHub |
MISC |
github.com |
|
| Release 0.24.0-rc1 · OpenSC/OpenSC · GitHub |
MISC |
github.com |
|
| cve-details |
MISC |
access.redhat.com |
|
| 2240912 – (CVE-2023-40660) CVE-2023-40660 OpenSC: Potential PIN bypass when card tracks its own login state |
MISC |
bugzilla.redhat.com |
|
| New release 0.24.0 · Issue #2792 · OpenSC/OpenSC · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161246 Oracle Enterprise Linux Security Update for opensc (ELSA-2023-7879)
- 161249 Oracle Enterprise Linux Security Update for opensc (ELSA-2023-7876)
- 242627 Red Hat Update for opensc (RHSA-2023:7879)
- 242631 Red Hat Update for opensc (RHSA-2023:7876)
- 284825 Fedora Security Update for opensc (FEDORA-2023-c7e4c9af51)
- 285094 Fedora Security Update for opensc (FEDORA-2023-a854153d7a)
- 356583 Amazon Linux Security Advisory for opensc : ALAS2-2023-2323
- 356637 Amazon Linux Security Advisory for opensc : ALAS2023-2023-417
- 379617 Alibaba Cloud Linux Security Update for opensc (ALINUX3-SA-2024:0026)
- 506145 Alpine Linux Security Update for opensc
- 6000352 Debian Security Update for opensc (DLA 3668-1)
- 755092 SUSE Enterprise Linux Security Update for opensc (SUSE-SU-2023:4089-1)
- 755099 SUSE Enterprise Linux Security Update for opensc (SUSE-SU-2023:4104-1)
- 941506 AlmaLinux Security Update for opensc (ALSA-2023:7876)
- 941511 AlmaLinux Security Update for opensc (ALSA-2023:7879)