LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2002-1446

CVE-2002-1446

CVSS 5 · MEDIUM

Summary

The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages.

CVSS 2.0 breakdown

Base score5 (MEDIUM)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Attack vectorNETWORK
Attack complexityLOW
ConfidentialityNONE
IntegrityPARTIAL
AvailabilityNONE

Affected products

Ncipher pkcs 11 library
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-16. Always verify against the vendor advisory before acting.

Scroll to Top