PIN Management Flaw in Yubico YubiKey 5 Devices
CVE-2020-15000

5.9MEDIUM

Key Information:

Vendor

Yubico

Vendor
CVE Published:
9 July 2020

What is CVE-2020-15000?

A vulnerability in Yubico YubiKey 5 devices affects the management of OpenPGP passwords. The flaw arises from a default setting where the Reset Code is initialized to a known value. This situation can be exploited if the retry counter for the Reset Code is not adjusted before use. Specifically, the Reset Code is used for resetting the User PIN, but it remains disabled by default. If the Admin PIN is inappropriately configured without changing the Reset Code value, an attacker can use the known initialization value to reset security credentials. Users and administrators should review their security settings to mitigate potential risks.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.