suse · CVE-2008-2235

Quick triage

Priority: medium Published: 2021-05-30 12:42:41 UTC Updated: 2026-04-18 20:27:33 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2008-2235 severity moderate: SUSE including 19 source package names (libopensc2-0.11.6-5.25.1, libopensc2-0.11.6-5.27.1, …), 34 product×package rows across 13 product lines (SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Server 11 SP1, … (13 product lines)): Fixed 30, Known Not Affected 4.

Description:

OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.

cvelogic Threat Intelligence