CVE Feed

    Dashboard / CVE / CVE-2020-15001

    CVE-2020-15001

    An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set optional access codes on OTP slots. This access code is intended to prevent unauthorized changes to OTP configurations. The access code is not checked when updating NFC specific components of the OTP configurations. This may allow an attacker to access configured OTPs and passwords stored in slots that were not configured by the user to be read over NFC, despite a user having set an access code. (Users who have not set an access code, or who have not configured the OTP slots, are not impacted by this issue.)

    Published:Jul 9, 2020
    Last Modified:Nov 21, 2024
    EPS:Jul 9, 2020
    EPSS Score:0.00084
    CVSS Score:5.3

    Affected Products

    Vendor
    Yubico
    Product
    Yubikey 5 Nfc
    Vendor
    Yubico
    Product
    Yubikey 5 Nfc Firmware

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High