CVE-2020-15001
Last modified
CVE-2020-15001 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set optional access codes on OTP slots. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set optional access codes on OTP slots. This access code is intended to prevent unauthorized changes to OTP configurations. The access code is not checked when updating NFC specific components of the OTP configurations. This may allow an attacker to access configured OTPs and passwords stored in slots that were not configured by the user to be read over NFC, despite a user having set an access code. (Users who have not set an access code, or who have not configured the OTP slots, are not impacted by this issue.)
Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Yubico | Yubikey 5 Nfc Firmware | >= 5.0.0, <= 5.2.6 |
| Yubico | Yubikey 5 Nfc Firmware | >= 5.3.0, <= 5.3.1 |
References
- https://www.yubico.com/support/security-advisories/ysa-2020-04/Exploit, Mitigation, Vendor Advisory
- https://www.yubico.com/support/security-advisories/ysa-2020-04/Exploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15001?
How severe is CVE-2020-15001?
How do I fix CVE-2020-15001?
Are you affected by CVE-2020-15001?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
