CVE Feed

    Dashboard / CVE / CVE-2021-31924

    CVE-2021-31924

    Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow user presence (touch) or cryptographic signature verification to be bypassed, so an attacker would still need to physically possess and interact with the YubiKey or another enrolled authenticator. If pam-u2f is configured to require PIN authentication, and the application using pam-u2f allows the user to submit NULL as the PIN, pam-u2f will attempt to perform a FIDO2 authentication without PIN. If this authentication is successful, the PIN requirement is bypassed.

    Published:May 25, 2021
    Last Modified:Nov 21, 2024
    EPS:May 25, 2021
    EPSS Score:0.00086
    CVSS Score:6.8

    Affected Products

    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Yubico
    Product
    Pam-u2f

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High