Yubico YubiKey 5
cpe:2.3:h:yubico:yubikey_5_nfc:*:*:*:*:*:*:*, +1 more
- >= 5.4.1, <= 5.7.3
A vulnerability exists in Yubico YubiKey 5.4.1 through 5.7.3 versions prior to 5.7.4, related to the FIDO CTAP PIN/UV Authentication Protocol Two. The issue arises because these YubiKey versions incorrectly apply the signature length from Protocol One during the verification process, leading to partial signature verification. This misalignment can create authentication issues, although the vulnerability is considered low severity due to the effort required to exploit it and existing mitigations within the YubiKey and FIDO protocol.
The vulnerability could lead to improper authentication by allowing a 16-byte signature, which is less secure, to be accepted when a 32-byte signature was required.
Users can update to YubiKey version 5.7.4 to address this vulnerability. For YubiKey models in the affected range, the update can be applied using the Yubico Authenticator.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.