ZeroHour

CVE-2023-39908

CVSS 3.1
7.5 high
EPSS
<1%p46
Published
()
Modified
Description

The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.

Vendors
yubico
Products
yubihsm 2 sdk
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.