VYPR

YubiHSM 2

by Yubico

CVEs (4)

  • CVE-2023-39908HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.00

    The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.

  • CVE-2021-32489MedMay 10, 2021
    risk 0.29cvss 4.4epss 0.01

    An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device because response_msg.st.len=8 can be accepted but triggers an…

  • CVE-2021-27217MedMar 4, 2021
    risk 0.29cvss 4.4epss 0.02

    An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device. Out-of-bounds reads performed by aes_remove_padding() can…

  • CVE-2024-45678MedSep 3, 2024
    risk 0.27cvss 4.2epss 0.00

    Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a…