CVE-2015-3298: High severity yubico yubikey 5ci vulnerability
Published Mar 29, 2022
·Updated
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.
Affected Software
1 affected component
Yubico ykneo-openpgp<1.0.10
Event History
Mar 29, 2022
CVE Published
via MITRE·11:16 PM
Data Sourced
via MITRE·11:16 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for Yubico ykneo-openpgp?
The vulnerability ID for Yubico ykneo-openpgp is CVE-2015-3298.
2
What is the severity of CVE-2015-3298?
The severity of CVE-2015-3298 is high with a severity value of 8.8.
3
How does CVE-2015-3298 affect Yubico ykneo-openpgp?
CVE-2015-3298 affects Yubico ykneo-openpgp version up to exclusive version 1.0.10.
4
What is the issue with Yubico ykneo-openpgp?
Yubico ykneo-openpgp has a typo in which an invalid PIN can be used, allowing a signature to be issued without validating the PIN.
5
How can I fix CVE-2015-3298 for Yubico ykneo-openpgp?
To fix CVE-2015-3298 for Yubico ykneo-openpgp, update to version 1.0.10 or higher.