CVE-2009-0368

Exp

OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.

Published: 2009-03-02 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2009-0368 is rated Exploit Available (50/100): CVSS Low severity, with medium exploitation likelihood (EPSS 1.21%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2009-0368

EDB-ID Source Kind Published Link
32820 exploit_db edb 2009-02-26 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2009-0368

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.36% 1.21% +0.85%
2 2026-03-02 0.31% 0.36% +0.05%
3 2025-05-28 0.31%

Full EPSS history (9 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2009-0368

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
2.1 2.0 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
3.9 2.9 [email protected]

Weakness enumeration for CVE-2009-0368

OS Trackers for CVE-2009-0368

vendor priority summary link
debian not yet assigned CVE-2009-0368 not yet assigned priority: Debian including 1 source packages (opensc), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2009-0368
gentoo normal CVE-2009-0368: 1 GLSA(s) (200908-01), 1 atom(s) (dev-libs/opensc); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2009-0368
redhat https://access.redhat.com/security/cve/CVE-2009-0368
suse low CVE-2009-0368 severity low: SUSE including 23 source package names (libopensc2-0.11.6-5.25.1, libopensc2-0.11.6-5.27.1, …), 61 product×package rows across 30 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (30 product lines)): Fixed 57, Known Not Affected 4. https://www.suse.com/security/cve/CVE-2009-0368/
ubuntu medium CVE-2009-0368 medium priority: Ubuntu including 1 source packages (opensc), 11 status rows across 11 suites (dapper, gutsy, hardy, intrepid, jaunty, karmic, lucid, maverick, natty, oneiric, upstream): not-affected 5, ignored 4, released 2. https://ubuntu.com/security/CVE-2009-0368

Affected software / configurations for CVE-2009-0368

Vendor Product Version Raw CPE
opensc-project opensc <= 0.11.6 cpe:2.3:a:opensc-project:opensc:*:*:*:*:*:*:*:*
opensc-project opensc 0.3.2 cpe:2.3:a:opensc-project:opensc:0.3.2:*:*:*:*:*:*:*
opensc-project opensc 0.3.5 cpe:2.3:a:opensc-project:opensc:0.3.5:*:*:*:*:*:*:*
opensc-project opensc 0.4.0 cpe:2.3:a:opensc-project:opensc:0.4.0:*:*:*:*:*:*:*
opensc-project opensc 0.5.0 cpe:2.3:a:opensc-project:opensc:0.5.0:*:*:*:*:*:*:*
opensc-project opensc 0.6.0 cpe:2.3:a:opensc-project:opensc:0.6.0:*:*:*:*:*:*:*
opensc-project opensc 0.6.1 cpe:2.3:a:opensc-project:opensc:0.6.1:*:*:*:*:*:*:*
opensc-project opensc 0.7.0 cpe:2.3:a:opensc-project:opensc:0.7.0:*:*:*:*:*:*:*
opensc-project opensc 0.8 cpe:2.3:a:opensc-project:opensc:0.8:*:*:*:*:*:*:*
opensc-project opensc 0.8.0 cpe:2.3:a:opensc-project:opensc:0.8.0:*:*:*:*:*:*:*
opensc-project opensc 0.8.0.0 cpe:2.3:a:opensc-project:opensc:0.8.0.0:*:*:*:*:*:*:*
opensc-project opensc 0.8.1 cpe:2.3:a:opensc-project:opensc:0.8.1:*:*:*:*:*:*:*
opensc-project opensc 0.9 cpe:2.3:a:opensc-project:opensc:0.9:*:*:*:*:*:*:*
opensc-project opensc 0.9.2 cpe:2.3:a:opensc-project:opensc:0.9.2:*:*:*:*:*:*:*
opensc-project opensc 0.9.3 cpe:2.3:a:opensc-project:opensc:0.9.3:*:*:*:*:*:*:*
opensc-project opensc 0.9.4 cpe:2.3:a:opensc-project:opensc:0.9.4:*:*:*:*:*:*:*
opensc-project opensc 0.9.5 cpe:2.3:a:opensc-project:opensc:0.9.5:*:*:*:*:*:*:*
opensc-project opensc 0.9.6 cpe:2.3:a:opensc-project:opensc:0.9.6:*:*:*:*:*:*:*
opensc-project opensc 0.9.7 cpe:2.3:a:opensc-project:opensc:0.9.7:*:*:*:*:*:*:*
opensc-project opensc 0.9.7 cpe:2.3:a:opensc-project:opensc:0.9.7:b:*:*:*:*:*:*
opensc-project opensc 0.9.7 cpe:2.3:a:opensc-project:opensc:0.9.7:d:*:*:*:*:*:*
opensc-project opensc 0.9.8 cpe:2.3:a:opensc-project:opensc:0.9.8:*:*:*:*:*:*:*
opensc-project opensc 0.10.0 cpe:2.3:a:opensc-project:opensc:0.10.0:*:*:*:*:*:*:*
opensc-project opensc 0.10.1 cpe:2.3:a:opensc-project:opensc:0.10.1:*:*:*:*:*:*:*
opensc-project opensc 0.11.0 cpe:2.3:a:opensc-project:opensc:0.11.0:*:*:*:*:*:*:*
opensc-project opensc 0.11.1 cpe:2.3:a:opensc-project:opensc:0.11.1:*:*:*:*:*:*:*
opensc-project opensc 0.11.2 cpe:2.3:a:opensc-project:opensc:0.11.2:*:*:*:*:*:*:*
opensc-project opensc 0.11.3 cpe:2.3:a:opensc-project:opensc:0.11.3:*:*:*:*:*:*:*
opensc-project opensc 0.11.3 cpe:2.3:a:opensc-project:opensc:0.11.3:pre3:*:*:*:*:*:*
opensc-project opensc 0.11.4 cpe:2.3:a:opensc-project:opensc:0.11.4:*:*:*:*:*:*:*
opensc-project opensc 0.11.5 cpe:2.3:a:opensc-project:opensc:0.11.5:*:*:*:*:*:*:*

References for CVE-2009-0368

URL Tags
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
http://openwall.com/lists/oss-security/2009/02/26/1 Patch
http://secunia.com/advisories/34052 Vendor Advisory
http://secunia.com/advisories/34120
http://secunia.com/advisories/34362
http://secunia.com/advisories/34377
http://secunia.com/advisories/35065
http://secunia.com/advisories/36074
http://security.gentoo.org/glsa/glsa-200908-01.xml
http://www.debian.org/security/2009/dsa-1734
http://www.opensc-project.org/pipermail/opensc-announce/2009-February/000023.html Vendor Advisory
http://www.securityfocus.com/bid/33922 Exploit Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/48958
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00673.html
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00686.html
cvelogic Threat Intelligence