Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2023-40660 Details

Description

A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS logon/screen unlock and for small, permanently connected tokens to computers. Additionally, the token can internally track login status. This flaw allows an attacker to gain unauthorized access, carry out malicious actions, or compromise the system without the user's awareness.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://access.redhat.com/errata/RHSA-2023:7876 CVE
https://access.redhat.com/errata/RHSA-2023:7879 CVE
https://access.redhat.com/security/cve/CVE-2023-40660 CVEThird Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2240912 CVEIssue Tracking
https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651 CVEIssue Tracking

see all 19 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-287Improper Authentication[email protected]
CWE-287Improper Authentication[email protected]

Affected Products

ProductVersions
opensc project opensc
<= 0.23.0

CPE

  • cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
redhat enterprise linux
8.0
9.0

CPE

  • cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

15 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2023-40660
NVD Published Date:
Nov 6, 2023
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2023-40660 Details - Not Deferred