CVE-2020-13131
Last modified
CVE-2020-13131 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. An issue was discovered in Yubico libykpiv before 2.1.0. lib/util.c in this library (which is included in yubico-piv-tool) does not properly check embedded length fields during device communication. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
An issue was discovered in Yubico libykpiv before 2.1.0. lib/util.c in this library (which is included in yubico-piv-tool) does not properly check embedded length fields during device communication. A malicious PIV token can misreport the returned length fields during RSA key generation. This will cause stack memory to be copied into heap allocated memory that gets returned to the caller. The leaked memory could include PINs, passwords, key material, and other sensitive information depending on the integration. During further processing by the caller, this information could leak across trust boundaries. Note that RSA key generation is triggered by the host and cannot directly be triggered by the token.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Yubico | Libykpiv | < 2.1.0 |
| Yubico | Piv Tool Manager | < 2.0.0 |
| Yubico | Yubikey Smart Card Minidriver | <= 4.1.0.172 |
References
- https://blog.inhq.net/posts/yubico-libykpiv-vuln/Exploit, Third Party Advisory
- https://blog.inhq.net/posts/yubico-libykpiv-vuln/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-13131?
How severe is CVE-2020-13131?
How do I fix CVE-2020-13131?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-13125An issue was discovered in the "Ultimate Addons for Elemento…6.5
- CVE-2020-13126An issue was discovered in the Elementor Pro plugin before 2…9.9
- CVE-2020-13127A SQL injection vulnerability at a tpf URI in Loway QueueMet…8.8
- CVE-2020-13128An issue was discovered in Manolo GWTUpload 1.0.3. server/Up…7.5
- CVE-2020-13129An issue was discovered in the stashcat app through 3.9.1 fo…7.2
- CVE-2020-1313An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-13132An issue was discovered in Yubico libykpiv before 2.1.0. An …4.6
- CVE-2020-13133Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vuln…6.1
- CVE-2020-13134Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vuln…4.8
- CVE-2020-13135D-Link DSP-W215 1.26b03 devices allow information disclosure…6.5
- CVE-2020-13136D-Link DSP-W215 1.26b03 devices send an obfuscated hash that…7.5
- CVE-2020-1314An elevation of privilege vulnerability exists in Windows Te…7.8
Are you affected by CVE-2020-13131?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
