CVE-2024-45616
Last modified
CVE-2024-45616 is a low-severity vulnerability rated 3.9/10 on the CVSS scale. A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caused by insufficient control of the response APDU buffer and its length when communicating with the card.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux | 9.0 |
| Opensc Project | Opensc | < 0.26.0 |
References
- https://access.redhat.com/security/cve/CVE-2024-45616Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2309290Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-45616?
How severe is CVE-2024-45616?
How do I fix CVE-2024-45616?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45610GLPI is an open-source asset and IT management software pack…6.1
- CVE-2024-45611GLPI is an open-source asset and IT management software pack…5.4
- CVE-2024-45612Contao is an Open Source CMS. In affected versions an untrus…5.3
- CVE-2024-45613CKEditor 5 is a JavaScript rich-text editor. Starting in ver…6.1
- CVE-2024-45614Puma is a Ruby/Rack web server built for parallelism. In aff…5.4
- CVE-2024-45615A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 m…3.9
- CVE-2024-45617A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 m…3.9
- CVE-2024-45618A vulnerability was found in pkcs15-init in OpenSC. An attac…3.9
- CVE-2024-45619A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 m…4.3
- CVE-2024-4562 In WhatsUp Gold versions released before 2023.1.2 , an SS…5.4
- CVE-2024-45620A vulnerability was found in the pkcs15-init tool in OpenSC.…3.9
- CVE-2024-45621The Electron desktop application of Rocket.Chat through 6.3.…5.4
Are you affected by CVE-2024-45616?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
