Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-81344
HistoryApr 18, 2022 - 12:00 a.m.

Yubico ykneo-openpgp data forgery issue vulnerability

2022-04-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
6

0.001 Low

EPSS

Percentile

35.0%

Yubico ykneo-openpgp is an open source security product from the Swedish company Yubico. It implements the OpenPGP card functionality used on YubiKey NEO devices sold by Yubico. A data forgery issue vulnerability exists in versions prior to Yubico ykneo-openpgp 1.0.10. The vulnerability stems from a spelling error in versions prior to Yubico ykneo-openpgp 1.0.10 that can be used with an invalid PIN. a signature is issued on first power-up, even if the PIN has not been verified. An attacker could use this vulnerability to obtain sensitive information.

CPENameOperatorVersion
yubico ykneo-openpgplt1.0.10

0.001 Low

EPSS

Percentile

35.0%

Related for CNVD-2022-81344