CVE-2021-43399 Information

Description

The Yubico YubiHSM YubiHSM2 library 2021.08 included in the yubihsm-shell project does not properly validate the length of some operations including SSH signing requests and some data operations received from a YubiHSM 2 device.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

https://www.yubico.com/support/security-advisories/ysa-2021-04/ https://blog.inhq.net/posts/yubico-yubihsm-shell-vuln3/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

7.5

Share on: