Operator Card Set Recovery Feature Bypass in nCipher: A Key to Application Key Breach

Operator Card Set Recovery Feature Bypass in nCipher: A Key to Application Key Breach

CVE-2001-0081 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.

Learn more about our User Device Pen Test.