{"api_version":"1","generated_at":"2026-07-23T06:49:21+00:00","cve":"CVE-2002-0940","urls":{"html":"https://cve.report/CVE-2002-0940","api":"https://cve.report/api/cve/CVE-2002-0940.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0940","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0940"},"summary":{"title":"CVE-2002-0940","description":"domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).","state":"PUBLISHED","assigner":"mitre","published_at":"2002-10-04 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://online.securityfocus.com/archive/1/277241","name":"http://online.securityfocus.com/archive/1/277241","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus HOME Mailing List: BugTraq","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4729","name":"http://www.securityfocus.com/bid/4729","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"nCipher MSCAPI CSP Install Wizard Incorrect Key Generation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2002-05/0103.html","name":"http://archives.neohapsis.com/archives/bugtraq/2002-05/0103.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Neohapsis Archives - Bugtraq - nCipher Security Advisory #3: MSCAPI CSP Install Wizard - From support@nCipher.com","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0940","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0940","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"940","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ncipher","cpe5":"mscapi_csp","cpe6":"5.50","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"940","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ncipher","cpe5":"mscapi_csp","cpe6":"5.54","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:03:49.374Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20020617 nCipher Advisory #3: MSCAPI keys erroneously module-protected - update","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://online.securityfocus.com/archive/1/277241"},{"name":"4729","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4729"},{"name":"20020513 nCipher Security Advisory #3: MSCAPI CSP Install Wizard","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-05/0103.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-06-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-09-10T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20020617 nCipher Advisory #3: MSCAPI keys erroneously module-protected - update","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://online.securityfocus.com/archive/1/277241"},{"name":"4729","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4729"},{"name":"20020513 nCipher Security Advisory #3: MSCAPI CSP Install Wizard","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-05/0103.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0940","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20020617 nCipher Advisory #3: MSCAPI keys erroneously module-protected - update","refsource":"BUGTRAQ","url":"http://online.securityfocus.com/archive/1/277241"},{"name":"4729","refsource":"BID","url":"http://www.securityfocus.com/bid/4729"},{"name":"20020513 nCipher Security Advisory #3: MSCAPI CSP Install Wizard","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2002-05/0103.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0940","datePublished":"2002-08-31T04:00:00.000Z","dateReserved":"2002-08-16T00:00:00.000Z","dateUpdated":"2024-08-08T03:03:49.374Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-10-04 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ncipher:mscapi_csp:5.50:*:*:*:*:*:*:*","matchCriteriaId":"A57D5F39-2B2F-4CB5-94AC-4D2CE4437104"},{"vulnerable":true,"criteria":"cpe:2.3:a:ncipher:mscapi_csp:5.54:*:*:*:*:*:*:*","matchCriteriaId":"7CE0D7EA-B2E0-4E49-B226-16D91DE67426"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"940","Ordinal":"1","Title":"CVE-2002-0940","CVE":"CVE-2002-0940","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"940","Ordinal":"1","NoteData":"domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).","Type":"Description","Title":"CVE-2002-0940"},{"CveYear":"2002","CveId":"940","Ordinal":"2","NoteData":"2002-08-31","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"940","Ordinal":"3","NoteData":"2002-09-10","Type":"Other","Title":"Modified"}]}}}