Information Leak in Yubico YubiKey 5 NFC Devices
CVE-2020-15001

5.3MEDIUM

Key Information:

Vendor

Yubico

Vendor
CVE Published:
9 July 2020

What is CVE-2020-15001?

An information leak exists in Yubico YubiKey 5 NFC devices that could allow unauthorized access to OTP configurations. Although users can set optional access codes on OTP slots to prevent unauthorized changes, this access code is not verified when updating NFC-specific components of the OTP configurations. As a result, attackers may gain access to OTPs and passwords stored in slots that were not intended for NFC reading, even if the user has set an access code. Notably, users without an access code or unconfigured OTP slots are not impacted by this issue.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.