Information Disclosure Vulnerability in OpenSC by LibOpenSC
CVE-2025-13763

5.7MEDIUM

What is CVE-2025-13763?

Multiple instances of uninitialized variables have been identified in LibOpenSC, potentially leading to information disclosure or application crashes. An attacker can exploit this vulnerability by using a specially crafted USB device or smart card that sends tailored responses to the APDUs, which may affect the integrity of the application or reveal sensitive information.

Affected Version(s)

OpenSC 0 < 0.27.0

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.