VYPR

YubiHSM 2

by Yubico

CVEs (2)

  • CVE-2024-45678Sep 3, 2024
    risk 0.00cvss epss 0.00

    Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a…

  • CVE-2023-39908Aug 14, 2023
    risk 0.00cvss epss 0.00

    The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.