search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Oberthur smart cards generate weak certificates

Vulnerability Note VU#659615

Original Release Date: 2012-11-09 | Last Revised: 2012-11-09

Overview

A flaw has been identified in Oberthur ID-One COSMO 64, v5.2 and v5.2a smart cards, which results in public keys that do not satisfy the requirements of the Digital Signature Standard (as specified in FIPS PUB 186-3 and its predecessors).

Description

Oberthur ID-One COSMO 64, v5.2 and v5.2a smart cards contain a flaw, which results in public keys that do not satisfy the requirements of the Digital Signature Standard (as specified in FIPS PUB 186-3 [PDF] and its predecessors).

Impact

An attacker may be able to adversely affect the integrity of the smart card identity.

Solution

Replace the smart card

Organizations should contact Oberthur Technologies through their regular support channels to determine if their smart cards are affected and to receive replacements.

Vendor Information

659615
 

Oberthur Affected

Updated:  November 09, 2012

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.


CVSS Metrics

Group Score Vector
Base 4 AV:L/AC:H/Au:N/C:N/I:C/A:N
Temporal 3.1 E:POC/RL:OF/RC:C
Environmental 2.3 CDP:ND/TD:M/CR:ND/IR:ND/AR:ND

References

Acknowledgements

Thanks to NSA IAD for reporting this vulnerability.

This document was written by Jared Allar.

Other Information

CVE IDs: None
Date Public: 2012-11-09
Date First Published: 2012-11-09
Date Last Updated: 2012-11-09 14:21 UTC
Document Revision: 22

Sponsored by CISA.