swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2000-12/0152.html | mailing list patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/5999 | vdb entry |
http://active.ncipher.com/updates/advisory.txt | patch vendor advisory |
http://www.osvdb.org/4849 | vdb entry |