CVE Feed

    Dashboard / CVE / CVE-2025-66215

    CVE-2025-66215

    OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.

    Published:Mar 30, 2026
    Last Modified:Apr 3, 2026
    EPS:Mar 30, 2026
    EPSS Score:0.0002
    CVSS Score:3.8

    Affected Products

    Vendor
    Opensc
    Product
    Opensc
    Vendor
    Opensc Project
    Product
    Opensc

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High