Vulnerability CVE-2022-24584


Published: 2022-05-11

Description:
Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP supposedly creates hardware bound second factor credentials. When a user reprograms the OTP functionality by "writing" it on a token using the Yubico Personalization Tool, they can then upload the new configuration to Yubicos OTP validation servers.

 References:
https://pastebin.com/7iLR1EbW
https://upload.yubico.com/
https://demo.yubico.com/otp/verify

Copyright 2026, cxsecurity.com

 

Back to Top