PT-2002-1948 · Ncipher · Ncipher Mscapi Csp

Publicado

2002-08-31

·

Atualizado

2008-09-10

·

CVE-2002-0939

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: nCipher MSCAPI CSP version 5.50
Description: The issue concerns the Install Wizard for nCipher MSCAPI CSP, which fails to utilize Operator Card Set protected keys as requested by the user when the Operator Card Set is not generated. This results in a lower protection level than what the user specified, providing only module protection.
Recommendations: For version 5.50, ensure that the Operator Card Set is properly generated when requesting protected keys to maintain the desired protection level. As a temporary workaround, consider manually verifying the protection level after installation to ensure it meets the user's requirements.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0939

Produtos afetados

Ncipher Mscapi Csp