Описание
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.
Ссылки
- ExploitMitigationVendor Advisory
- ExploitMitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.10 (исключая)
cpe:2.3:a:yubico:ykneo-openpgp:*:*:*:*:*:*:*:*
EPSS
Процентиль: 32%
0.00126
Низкий
8.8 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-347
Связанные уязвимости
CVSS3: 8.8
github
почти 4 года назад
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.
EPSS
Процентиль: 32%
0.00126
Низкий
8.8 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-347