PT-2025-7057 · Nitrokey · Nitrokey 3 Firmware

Published

2025-02-12

·

Updated

2025-02-12

·

CVE-2025-25201

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Nitrokey 3 Firmware versions 1.8.0 and prior test releases with PIV enabled
Description: The PIV application in the Nitrokey 3 Firmware could accept invalid keys for authentication of the admin key, potentially compromising the integrity of the data stored in the application. An attacker without access to the proper administration key could generate new keys and overwrite certificates, but would not be able to read or extract existing private data, nor gain access to cryptographic operations that require PIN-based authentication.
Recommendations: For Nitrokey 3 Firmware version 1.8.0 and prior test releases with PIV enabled, update to firmware version 1.8.1 to resolve the issue. As a temporary workaround, consider restricting access to the PIV application until the update is applied.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-25201
GHSA-JFHM-PPQ8-7HGX

Affected Products

Nitrokey 3 Firmware