Логотип exploitDog
bind:"GHSA-wwr4-cj7g-985f" OR bind:"CVE-2025-23013"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-wwr4-cj7g-985f" OR bind:"CVE-2025-23013"

Количество 10

Количество 10

github логотип

GHSA-wwr4-cj7g-985f

11 месяцев назад

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

EPSS: Низкий
ubuntu логотип

CVE-2025-23013

11 месяцев назад

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

EPSS: Низкий
nvd логотип

CVE-2025-23013

11 месяцев назад

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

EPSS: Низкий
debian логотип

CVE-2025-23013

11 месяцев назад

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometim ...

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0200-1

10 месяцев назад

Security update for pam_u2f

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0198-1

10 месяцев назад

Security update for pam_u2f

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0192-1

11 месяцев назад

Security update for pam_u2f

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0167-1

11 месяцев назад

Security update for pam_u2f

EPSS: Низкий
fstec логотип

BDU:2025-02595

около 1 года назад

Уязвимость функции pam_sm_authenticate() PAM-модуля Yubico pam-u2f, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20251014-02

около 2 месяцев назад

Уязвимость pam-u2f

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-wwr4-cj7g-985f

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-23013

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-23013

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-23013

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometim ...

0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0200-1

Security update for pam_u2f

0%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0198-1

Security update for pam_u2f

0%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0192-1

Security update for pam_u2f

0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0167-1

Security update for pam_u2f

0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-02595

Уязвимость функции pam_sm_authenticate() PAM-модуля Yubico pam-u2f, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.8
0%
Низкий
около 1 года назад
redos логотип
ROS-20251014-02

Уязвимость pam-u2f

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу