PT-2002-1948 · Ncipher · Ncipher Mscapi Csp
Published
2002-08-31
·
Updated
2008-09-10
·
CVE-2002-0939
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
nCipher MSCAPI CSP version 5.50
Description:
The issue concerns the Install Wizard for nCipher MSCAPI CSP, which fails to utilize Operator Card Set protected keys as requested by the user when the Operator Card Set is not generated. This results in a lower protection level than what the user specified, providing only module protection.
Recommendations:
For version 5.50, ensure that the Operator Card Set is properly generated when requesting protected keys to maintain the desired protection level. As a temporary workaround, consider manually verifying the protection level after installation to ensure it meets the user's requirements.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ncipher Mscapi Csp