VYPR

YubiKey

by Yubico

CVEs (5)

  • CVE-2022-24584MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP supposedly creates hardware bound second factor credentials. When a user reprograms the OTP functionality by "writing" it on a token…

  • CVE-2020-15000MedJul 9, 2020
    risk 0.38cvss 5.9epss 0.01

    A PIN management problem was discovered on Yubico YubiKey 5 devices 5.2.0 to 5.2.6. OpenPGP has three passwords: Admin PIN, Reset Code, and User PIN. The Reset Code is used to reset the User PIN, but it is disabled by default. A flaw in the implementation of OpenPGP sets the…

  • CVE-2020-15001MedJul 9, 2020
    risk 0.34cvss 5.3epss 0.01

    An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set optional access codes on OTP slots. This access code is intended to prevent unauthorized changes to OTP configurations. The access code…

  • CVE-2021-3011MedJan 7, 2021
    risk 0.27cvss 4.2epss 0.00

    An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.9. It allows attackers to extract the ECDSA private key after extensive physical access (and…

  • CVE-2025-29991LowApr 3, 2025
    risk 0.14cvss 2.2epss 0.00

    Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, resulting in a partial signature verification.