Impact
The vulnerability resides in the setcos_construct_fci_44 function in OpenSC's card-setcos.c module, where manipulating the type_attr argument can overflow a stack buffer, potentially allowing an attacker to execute arbitrary code. This flaw is a classic stack-based buffer overflow (CWE-119 and CWE-121). The exploit would allow memory corruption, leading to compromised confidentiality, integrity, or availability of any system utilizing the affected OpenSC library.
Affected Systems
All installations of OpenSC up to and including version 0.27.1 are affected. The vulnerability manifests in any environment where the library is invoked for Smart Card operations, especially over networked or remote connections.
Risk and Exploitability
The CVSS base score of 5.1 indicates a medium severity, but the remote attack vector implies that an adversary could target the vulnerable component from outside the host. EPSS data is currently unavailable, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting limited known exploitation at this time. Nevertheless, the lack of patching in exposed systems poses a potential risk that should be mitigated promptly.
OpenCVE Enrichment