Denial of Service Vulnerability in Yubihsm-shell by Yubico
CVE-2020-24388
7.5HIGH
What is CVE-2020-24388?
A vulnerability in the _send_secure_msg() function of Yubico's yubihsm-shell allows for unmatched length field validation in messages from the device. This oversight can lead to oversized memory copy operations, potentially crashing the process. As a result, attackers could exploit this flaw to induce a denial of service, affecting system availability.