High severity7.5NVD Advisory· Published Dec 8, 2021· Updated Jun 17, 2026
CVE-2021-43399
CVE-2021-43399
Description
The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the length of some operations including SSH signing requests, and some data operations received from a YubiHSM 2 device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 2021.08
- Range: 2021.08
- Yubico YubiHSM/YubiHSM2 librarydescription
- cpe:2.3:a:yubico:yubihsm_2_software_development_kit:*:*:*:*:*:*:*:*Range: <=2021.08
Patches
Vulnerability mechanics
References
2- blog.inhq.net/posts/yubico-yubihsm-shell-vuln3/nvdExploitThird Party Advisory
- www.yubico.com/support/security-advisories/ysa-2021-04/nvdVendor Advisory
News mentions
0No linked articles in our index yet.