CVE Explorer
CVE-2025-66038
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and value length (low nibble). With a 1-byte buffer {0x0A}, the encoded element claims tag=0 and length=10 but no value bytes follow. Calling sc_compacttlv_find_tag with search tag 0x00 returns a pointer equal to buf+1 and outlen=10 without verifying that the claimed value length fits w
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"OpenSC","vendor":"OpenSC","versions":[{"status":"affected","version":"< 0.27.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f289703812cc0aba8b986afa4d60b9540b6c623ce268059ad47d848ccaf24c96 · sha256:4260916fd8fd5b06… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"PHYSICAL","availabilityImpact":"LOW","baseScore":3.9,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f289703812cc0aba8b986afa4d60b9540b6c623ce268059ad47d848ccaf24c96 · sha256:4260916fd8fd5b06… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-126","description":"CWE-126: Buffer Over-read","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f289703812cc0aba8b986afa4d60b9540b6c623ce268059ad47d848ccaf24c96 · sha256:4260916fd8fd5b06… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/OpenSC/OpenSC/commit/6db171bcb6fd7cb3b51098fefbb3b28e44f0a79c","tags":["x_refsource_MISC"],"url":"https://github.com/OpenSC/OpenSC/commit/6db171bcb6fd7cb3b51098fefbb3b28e44f0a79c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f289703812cc0aba8b986afa4d60b9540b6c623ce268059ad47d848ccaf24c96 · sha256:4260916fd8fd5b06… · /containers/cna/references/1
{"name":"https://github.com/OpenSC/OpenSC/security/advisories/GHSA-72x5-fwjx-2459","tags":["x_refsource_CONFIRM"],"url":"https://github.com/OpenSC/OpenSC/security/advisories/GHSA-72x5-fwjx-2459"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f289703812cc0aba8b986afa4d60b9540b6c623ce268059ad47d848ccaf24c96 · sha256:4260916fd8fd5b06… · /containers/cna/references/0
{"name":"https://github.com/OpenSC/OpenSC/wiki/CVE-2025-66038","tags":["x_refsource_MISC"],"url":"https://github.com/OpenSC/OpenSC/wiki/CVE-2025-66038"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f289703812cc0aba8b986afa4d60b9540b6c623ce268059ad47d848ccaf24c96 · sha256:4260916fd8fd5b06… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.