Local PIN Bypass Vulnerability in Yubico PAM-U2F
CVE-2021-31924
What is CVE-2021-31924?
Yubico's pam-u2f prior to version 1.1.1 contains a logic flaw that may permit attackers to bypass the PIN requirement through specific configurations. This vulnerability arises when pam-u2f is set to require PIN authentication, and attended applications inadvertently permit NULL submissions as the PIN. Successfully exploiting this weakness allows the authentication process to proceed without the necessary PIN, enabling FIDO2 authentication while neglecting the PIN, provided the attacker has physical access to the YubiKey or an equivalent registered authenticator.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
