NA

CVE-2023-39908

Published: 14/08/2023 Updated: 25/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The PKCS11 module of the YubiHSM 2 SDK up to and including 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.

Vulnerable Product Search on Vulmon Subscribe to Product

yubico yubihsm 2 sdk