CVE-2025-29991: Low severity yubico yubikey vulnerability
Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, resulting in a partial signature verification.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29991?
CVE-2025-29991 is classified as a medium severity vulnerability due to its impact on signature verification.
How do I fix CVE-2025-29991?
To mitigate CVE-2025-29991, upgrade your YubiKey firmware to version 5.7.4 or later.
What versions of YubiKey are affected by CVE-2025-29991?
YubiKey versions 5.4.1 through 5.7.3 are affected by CVE-2025-29991.
What is the impact of CVE-2025-29991 on YubiKey users?
CVE-2025-29991 can lead to improper signature verification during authentication, potentially compromising security.
Is there a workaround for CVE-2025-29991?
There are no known workarounds for CVE-2025-29991, making firmware upgrade the recommended solution.