CVE-2023-40660

Public on 2023-10-06
Modified on 2024-01-31
Description
Potential PIN bypass.
When the token/card was plugged into the computer and authenticated from one process, it could be used to provide cryptographic operations from different process when the empty, zero-length PIN and the token can track the login status using some of its internals. This is dangerous for OS logon/screen unlock and small tokens that are plugged permanently to the computer.
Severity
Medium severity
Medium
CVSS v3 Base Score
6.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core opensc 2023-10-30 ALAS2-2023-2323 Fixed
Amazon Linux 2023 opensc 2023-10-30 ALAS2023-2023-417 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NVD CVSSv3 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H