CVE-2024-45620: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.
AI Analysis
Technical Summary
The vulnerability in OpenSC's pkcs15-init tool involves a classic buffer overflow due to copying data without checking the size of input buffers. An attacker controlling a USB device or smart card can send malicious APDU responses that cause the tool to access partially initialized buffers incorrectly. This can lead to information disclosure, integrity, and availability impacts as indicated by the CVSS vector. The issue is documented under CVE-2024-45620 with a CVSS 3.9 (low) score and is publicly disclosed with a Red Hat advisory available.
Potential Impact
The vulnerability allows an attacker with physical access to present a malicious USB device or smart card that triggers buffer overflow conditions in pkcs15-init. This can result in limited confidentiality, integrity, and availability impacts. The CVSS score reflects low severity, indicating the impact is not critical or high. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2024-45620 for current remediation guidance. No official fix or patch information is provided in the available data. Until a patch is available, restrict use of untrusted USB devices and smart cards to reduce risk.
CVE-2024-45620: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Description
A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.
CVSS v3.1
Score 3.9low
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in OpenSC's pkcs15-init tool involves a classic buffer overflow due to copying data without checking the size of input buffers. An attacker controlling a USB device or smart card can send malicious APDU responses that cause the tool to access partially initialized buffers incorrectly. This can lead to information disclosure, integrity, and availability impacts as indicated by the CVSS vector. The issue is documented under CVE-2024-45620 with a CVSS 3.9 (low) score and is publicly disclosed with a Red Hat advisory available.
Potential Impact
The vulnerability allows an attacker with physical access to present a malicious USB device or smart card that triggers buffer overflow conditions in pkcs15-init. This can result in limited confidentiality, integrity, and availability impacts. The CVSS score reflects low severity, indicating the impact is not critical or high. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2024-45620 for current remediation guidance. No official fix or patch information is provided in the available data. Until a patch is available, restrict use of untrusted USB devices and smart cards to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2024-09-02T18:28:35.896Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2024-45620","vendor":"Red Hat"}]
Threat ID: 69092b7735043901e828cb29
Added to database: 11/03/2025, 22:23:51 UTC
Last enriched: 07/02/2026, 22:01:11 UTC
Last updated: 07/15/2026, 07:47:24 UTC
Views: 230
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.