PT-2002-1948 · Ncipher · Ncipher Mscapi Csp

Published

2002-08-31

·

Updated

2008-09-10

·

CVE-2002-0939

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: nCipher MSCAPI CSP version 5.50
Description: The issue concerns the Install Wizard for nCipher MSCAPI CSP, which fails to utilize Operator Card Set protected keys as requested by the user when the Operator Card Set is not generated. This results in a lower protection level than what the user specified, providing only module protection.
Recommendations: For version 5.50, ensure that the Operator Card Set is properly generated when requesting protected keys to maintain the desired protection level. As a temporary workaround, consider manually verifying the protection level after installation to ensure it meets the user's requirements.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0939

Affected Products

Ncipher Mscapi Csp