Incorrect access control in Yubico OTP functionality of...
Moderate severity
Unreviewed
Published
May 12, 2022
to the GitHub Advisory Database
•
Updated Mar 30, 2024
Description
Published by the National Vulnerability Database
May 11, 2022
Published to the GitHub Advisory Database
May 12, 2022
Last updated
Mar 30, 2024
Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP supposedly creates hardware bound second factor credentials. When a user reprograms the OTP functionality by "writing" it on a token using the Yubico Personalization Tool, they can then upload the new configuration to Yubicos OTP validation servers.
References