CVE-2025-24531

EUVD-2025-206298
In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered by a smartcard before login), allowing authentication bypass.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
mitreCNA
6.7 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
pam-pkcs11
bookworm
0.6.12-1+deb12u1
fixed
bookworm (security)
0.6.12-1+deb12u1
fixed
bullseye
0.6.11-4
not-affected
bullseye (security)
0.6.11-4+deb11u1
fixed
forky
0.6.13-1
fixed
sid
0.6.13-1
fixed
trixie
0.6.13-1
fixed