PT-2025-7057 · Nitrokey · Nitrokey 3 Firmware
Published
2025-02-12
·
Updated
2025-02-12
·
CVE-2025-25201
CVSS v3.1
4.0
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Nitrokey 3 Firmware versions 1.8.0 and prior test releases with PIV enabled
Description:
The PIV application in the Nitrokey 3 Firmware could accept invalid keys for authentication of the admin key, potentially compromising the integrity of the data stored in the application. An attacker without access to the proper administration key could generate new keys and overwrite certificates, but would not be able to read or extract existing private data, nor gain access to cryptographic operations that require PIN-based authentication.
Recommendations:
For Nitrokey 3 Firmware version 1.8.0 and prior test releases with PIV enabled, update to firmware version 1.8.1 to resolve the issue.
As a temporary workaround, consider restricting access to the PIV application until the update is applied.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nitrokey 3 Firmware