Information Leak in Yubico YubiKey 5 NFC Devices
CVE-2020-15001
What is CVE-2020-15001?
An information leak exists in Yubico YubiKey 5 NFC devices that could allow unauthorized access to OTP configurations. Although users can set optional access codes on OTP slots to prevent unauthorized changes, this access code is not verified when updating NFC-specific components of the OTP configurations. As a result, attackers may gain access to OTPs and passwords stored in slots that were not intended for NFC reading, even if the user has set an access code. Notably, users without an access code or unconfigured OTP slots are not impacted by this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
