CVE-2001-0081 Information

Description

swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user which could allow attackers to gain access to application keys.

Reference

http://active.ncipher.com/updates/advisory.txt http://archives.neohapsis.com/archives/bugtraq/2000-12/0152.html http://www.osvdb.org/4849 https://exchange.xforce.ibmcloud.com/vulnerabilities/5999

Share on: