CVE-2024-35311: Low severity Yubico YubiKey 5 Series vulnerability
Yubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 FIPS before 5.7.2 have Incorrect Access Control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35311?
The severity of CVE-2024-35311 is high due to its incorrect access control, which can lead to unauthorized access.
How do I fix CVE-2024-35311?
To mitigate CVE-2024-35311, users should update their YubiKey devices to versions 5.7.0 or later for YubiKey 5 Series and Security Key Series, and to versions 5.6.4 or later for YubiKey Bio Series, and 5.7.2 or later for YubiKey 5 FIPS.
What products are affected by CVE-2024-35311?
CVE-2024-35311 affects YubiKey 5 Series prior to version 5.7.0, Security Key Series prior to version 5.7.0, YubiKey Bio Series prior to version 5.6.4, and YubiKey 5 FIPS prior to version 5.7.2.
What risks are associated with CVE-2024-35311?
Risks associated with CVE-2024-35311 include potential unauthorized access to sensitive information or systems due to the incorrect access control vulnerability.
Is there a workaround for CVE-2024-35311?
While the best solution is to update to the latest versions, users can minimize risk by implementing additional security measures until they can update.