Out-of-Bounds Read and Write in YubiHSM Shell by Yubico
CVE-2020-24387
7.5HIGH
What is CVE-2020-24387?
An issue in the yh_create_session() function of YubiHSM Shell allows for improper validation of the session ID returned from the device. This oversight can lead to out-of-bounds read and write operations within the session array. An attacker can exploit this vulnerability to orchestrate a denial of service attack, potentially disrupting the operations of affected systems. Users of YubiHSM Shell are urged to apply necessary mitigations and check for updates to secure their environments.