Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (2.9)0.13%—Yubico Libfido2AIYubico Python-fido2AIYubico Yubikey-managerAI16/4/202617/6/2026
Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.
AplazadaBaja (2.2)0.12%—Yubico YubikeyAI3/4/202517/6/2026
Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, resulting in a partial signature verification.
ModificadaMedia (4.2)0.33%—Yubico Yubikey 5C NFC FirmwareYubico Yubikey 5 NFC FirmwareYubico Yubikey 5C FirmwareYubico Yubikey 5 Nano Firmware+143/9/202417/6/2026
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the…
AplazadaBaja (3.3)0.15%—Yubico Yubikey 5 SeriesAIYubico Security KEY SeriesAIYubico Yubikey BIO SeriesAIYubico Yubikey 5 FipsAI29/5/202417/6/2026
Yubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 FIPS before 5.7.2 have Incorrect Access Control.
ModificadaMedia (4.2)0.20%—Ftsafe K13Ftsafe K21Ftsafe K40Ftsafe K9+417/1/202117/6/2026
An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.9. It allows attackers to extract the ECDSA private key after extensive physical access (and consequently produce a clone). This was…
ModificadaMedia (5.3)0.55%—Yubico Yubikey 5 NFC Firmware9/7/202017/6/2026
An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set optional access codes on OTP slots. This access code is intended to prevent unauthorized changes to OTP configurations. The access code is not checked when updating NFC…
ModificadaMedia (5.9)0.70%—Yubico Yubikey 5 NFC Firmware9/7/202017/6/2026
A PIN management problem was discovered on Yubico YubiKey 5 devices 5.2.0 to 5.2.6. OpenPGP has three passwords: Admin PIN, Reset Code, and User PIN. The Reset Code is used to reset the User PIN, but it is disabled by default. A flaw in the implementation of OpenPGP sets the Reset Code to a known value upon…
ModificadaMedia (4.6)0.64%—Yubico LibykpivYubico PIV Tool ManagerYubico Yubikey Smart Card Minidriver9/7/202017/6/2026
An issue was discovered in Yubico libykpiv before 2.1.0. An attacker can trigger an incorrect free() in the ykpiv_util_generate_key() function in lib/util.c through incorrect error handling code. This could be used to cause a denial of service attack.
ModificadaMedia (4.3)0.49%—Yubico LibykpivYubico PIV Tool ManagerYubico Yubikey Smart Card Minidriver9/7/202017/6/2026
An issue was discovered in Yubico libykpiv before 2.1.0. lib/util.c in this library (which is included in yubico-piv-tool) does not properly check embedded length fields during device communication. A malicious PIV token can misreport the returned length fields during RSA key generation. This will cause stack memory…
ModificadaAlta (8.6)1.5%—Yubico Yubikey ONE Time Password Validation Server5/3/202017/6/2026
The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service with a non-default configuration such as an open sync pool; the issue does NOT affect YubiCloud.
ModificadaAlta (7.5)1.5%—Yubico Yubikey ONE Time Password Validation Server5/3/202017/6/2026
The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service; the issue does NOT…
Orbitaley — Vulnerabilidades