CVE-2025-24531

Published
View on NVD ↗
CVSS v3
6.7
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered by a smartcard before login), allowing authentication bypass.

This Linux-PAM login module allows a X.509 certificate based user login
GitHubGitHub
77