SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#214555

Multiple vulnerabilities exist within credit card chips thereby allowing malicious user to bypass authentication mechanism

Overview

French smart card reader terminals can be fooled into accepting imposter smart cards for payment.

I. Description

French smart cards are credit cards with an embedded chip containing certain cardholder, account, and authentication information. These cards are read by automated terminals across France for sale of a variety of products and services.

Prior to November 1999, authentication was performed on the terminals by reading a 320-bit RSA-encrypted authentication value from card, decrypting the value, and comparing it to the unencrypted account information stored on the card. The encryption method used a 321-bit RSA key which was cracked in or before 1998 and published on the Internet on February 9, 2000. With knowledge of the key now public, criminals have begun to forge their own credit cards with valid authentication values on bogus accounts. Because the terminals check only the information stored on the card without verifying the account validity with the credit card issuer, the terminals are fooled into accepting the card and dispensing product or providing services.

Starting in November 1999, new smart cards contained a second authentication value of 768 bits. However, with 37 million of the old cards already in service, most terminals were either not upgraded to use the new authentication scheme or were upgraded with backward compatibility enabled for the older cards.

II. Impact

Attackers can forge smart cards that will be accepted as payment at over two million estimated automated card reader terminals in France.

III. Solution

Merchants should upgrade their smart card reader terminals to require the new authentication scheme introduced in November 1999. Cardholders of cards issued before November 1999 should obtain new cards.

Systems Affected

VendorStatusDate NotifiedDate Updated
Groupement des Cartes BancairesVulnerable7-Jun-2002

References


http://parodie.com/monetique/
http://www.cartes-bancaires.com/GB/Pages/Accueil2.htm

Credit

Thanks to Laurent Pele for reporting this vulnerability.

This document was written by Shawn Van Ittersum.

Other Information

Date Public:2000-02-09
Date First Published:2002-09-18
Date Last Updated:2002-09-18
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Metric:0.18
Document Revision:7

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2002 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader