swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2000-12/0152.html | Patch Vendor Advisory |
http://active.ncipher.com/updates/advisory.txt | Patch Vendor Advisory |
http://www.osvdb.org/4849 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/5999 |
Configurations
Information
Published : 2001-02-11 21:00
Updated : 2017-10-09 18:29
NVD link : CVE-2001-0081
Mitre link : CVE-2001-0081
JSON object : View
CWE
Products Affected
ncipher
- ncipher