cbcvebase.

Yubico Yubihsm-Shell vulnerabilities

4 known vulnerabilities affecting yubico/yubihsm-shell.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2020-24387P3HIGHCVSS 7.5≤ 2.0.22020-10-19
CVE-2020-24387 [HIGH] CWE-125 CVE-2020-24387: An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The func An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write operations in the session array. This could be used by an attacker to cause a denial of service attack.
nvd
CVE-2020-24388P3HIGHCVSS 7.5≤ 2.0.22020-10-19
CVE-2020-24388 [HIGH] CWE-20 CVE-2020-24388: An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The funct An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This could be used by an attacker to cause a denial of service.
nvd
CVE-2021-27217P4MEDIUMCVSS 4.4≤ 2.0.32021-03-04
CVE-2021-27217 [MEDIUM] CWE-125 CVE-2021-27217: An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. Th An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device. Out-of-bounds reads performed by aes_remove_padding() can crash the running process, depending on the memory layout. This could be u
nvd
CVE-2021-32489P4MEDIUMCVSS 4.4≤ 2.0.32021-05-10
CVE-2021-32489 [MEDIUM] CWE-190 CVE-2021-32489: An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. Th An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device because response_msg.st.len=8 can be accepted but triggers an integer overflow, which causes CRYPTO_cbc128_decrypt (in OpenSSL) to en
nvd
Yubico Yubihsm-Shell vulnerabilities | cvebase