PT-2025-14572 · Yubico · Yubikey

Published

2025-04-03

·

Updated

2025-04-03

·

CVE-2025-29991

CVSS v3.1

2.2

Low

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Yubico YubiKey versions 5.4.1 through 5.7.3
Description The issue is related to an incorrect implementation of the FIDO CTAP PIN/UV 2 authentication protocol. Specifically, it uses the signature length from the CTAP PIN/UV 1 protocol, even when the CTAP PIN/UV 2 protocol is chosen, resulting in partial signature verification.
Recommendations For versions 5.4.1 through 5.7.3, update to version 5.7.4 or later to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-29991

Affected Products

Yubikey