PT-2022-7826 · Yubico · Ykneo-Openpgp

Joey Castillo

·

Published

2022-03-29

·

Updated

2022-04-08

·

CVE-2015-3298

CVSS v2.0

5.8

Medium

VectorAV:A/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Yubico ykneo-openpgp versions prior to 1.0.10
Description The issue is caused by a typo, allowing an invalid PIN to be used. When the device is first powered up, a signature will be issued even though the PIN has not been validated.
Recommendations For versions prior to 1.0.10, update to version 1.0.10 or later to resolve the issue. As a temporary workaround, consider disabling the use of the device until a patch is available. Restrict access to the device to minimize the risk of exploitation.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3298

Affected Products

Ykneo-Openpgp