CVE-2024-45619: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.
AI Analysis
Technical Summary
This vulnerability involves a classic buffer overflow due to copying data without checking the size of input buffers in OpenSC and related components. An attacker controlling a USB device or smart card can present malicious APDU responses that cause the software to incorrectly access or use partially initialized buffer data. This can result in a buffer overflow condition with potential impacts on confidentiality, integrity, and availability. The CVSS 3.1 base score is 4.3, reflecting a medium severity with attack vector as physical (local device), low attack complexity, no privileges required, and no user interaction needed. The vendor advisory from Red Hat is available but does not explicitly state patch availability or mitigation steps in the provided content.
Potential Impact
Successful exploitation could allow an attacker with physical access (via a crafted USB device or smart card) to cause a buffer overflow, potentially leading to information disclosure, data integrity compromise, or denial of service. The CVSS vector indicates impacts on confidentiality, integrity, and availability, but the overall severity is medium.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2024-45619 for current remediation guidance. Until a patch is confirmed, limit exposure by restricting use of untrusted USB devices or smart cards. Follow vendor instructions once available.
CVE-2024-45619: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Description
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.
CVSS v3.1
Score 4.3medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves a classic buffer overflow due to copying data without checking the size of input buffers in OpenSC and related components. An attacker controlling a USB device or smart card can present malicious APDU responses that cause the software to incorrectly access or use partially initialized buffer data. This can result in a buffer overflow condition with potential impacts on confidentiality, integrity, and availability. The CVSS 3.1 base score is 4.3, reflecting a medium severity with attack vector as physical (local device), low attack complexity, no privileges required, and no user interaction needed. The vendor advisory from Red Hat is available but does not explicitly state patch availability or mitigation steps in the provided content.
Potential Impact
Successful exploitation could allow an attacker with physical access (via a crafted USB device or smart card) to cause a buffer overflow, potentially leading to information disclosure, data integrity compromise, or denial of service. The CVSS vector indicates impacts on confidentiality, integrity, and availability, but the overall severity is medium.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2024-45619 for current remediation guidance. Until a patch is confirmed, limit exposure by restricting use of untrusted USB devices or smart cards. Follow vendor instructions once available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2024-09-02T18:28:35.896Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2024-45619","vendor":"Red Hat"}]
Threat ID: 69092b7735043901e828cb24
Added to database: 11/03/2025, 22:23:51 UTC
Last enriched: 07/02/2026, 22:01:04 UTC
Last updated: 09/10/2026, 19:36:48 UTC
Views: 230
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.