#VU82973 Improper Authorization in OpenSC - CVE-2023-40660
Published: November 10, 2023
OpenSC
OpenSC
Description
The vulnerability allows an attacker to bypass authorization process.
The vulnerability exists due to a logic error in the authorization process. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. An attacker with physical proximity to the system can bypass the OS logon/screen for small permanently connected tokens to computers.