Yubico YubiKey FIDO CTAP PIN/UV Auth Protocol Two Implementation Vulnerability

Vulnerability

A vulnerability exists in Yubico YubiKey 5.4.1 through 5.7.3 versions prior to 5.7.4, related to the FIDO CTAP PIN/UV Authentication Protocol Two. The issue arises because these YubiKey versions incorrectly apply the signature length from Protocol One during the verification process, leading to partial signature verification. This misalignment can create authentication issues, although the vulnerability is considered low severity due to the effort required to exploit it and existing mitigations within the YubiKey and FIDO protocol.

Impact

The vulnerability could lead to improper authentication by allowing a 16-byte signature, which is less secure, to be accepted when a 32-byte signature was required.

Remediation

Users can update to YubiKey version 5.7.4 to address this vulnerability. For YubiKey models in the affected range, the update can be applied using the Yubico Authenticator.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
1.3
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.