Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

fstec логотип

BDU:2025-02595

больше 1 года назад

Уязвимость функции pam_sm_authenticate() PAM-модуля Yubico pam-u2f, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20251014-02

10 месяцев назад

Уязвимость pam-u2f

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2025-23013

больше 1 года назад

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

EPSS: Низкий
nvd логотип

CVE-2025-23013

больше 1 года назад

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

EPSS: Низкий
debian логотип

CVE-2025-23013

больше 1 года назад

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometim ...

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0200-1

больше 1 года назад

Security update for pam_u2f

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0198-1

больше 1 года назад

Security update for pam_u2f

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0192-1

больше 1 года назад

Security update for pam_u2f

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0167-1

больше 1 года назад

Security update for pam_u2f

EPSS: Низкий
github логотип

GHSA-wwr4-cj7g-985f

больше 1 года назад

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-02595

Уязвимость функции pam_sm_authenticate() PAM-модуля Yubico pam-u2f, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.8
0%
Низкий
больше 1 года назад
redos логотип
ROS-20251014-02

Уязвимость pam-u2f

CVSS3: 7.8
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2025-23013

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-23013

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-23013

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometim ...

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0200-1

Security update for pam_u2f

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0198-1

Security update for pam_u2f

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0192-1

Security update for pam_u2f

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0167-1

Security update for pam_u2f

0%
Низкий
больше 1 года назад
github логотип
GHSA-wwr4-cj7g-985f

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

0%
Низкий
больше 1 года назад

Уязвимостей на страницу