CVE-2020-13131 is a medium-severity vulnerability in Yubico libykpiv before version 2.1.0, affecting products like yubico-piv-tool. It allows a malicious PIV token to misreport length fields during RSA key generation, leading to sensitive stack memory (potentially including PINs, passwords, or key material) being copied into heap-allocated memory and returned to the caller. The attack requires physical access to the device (AV:P) and user interaction (UI:R) to trigger RSA key generation, but is otherwise low complexity (AC:L). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.0CPE matchmatch criteria | cpe:2.3:a:yubico:libykpiv:*:*:*:*:*:*:*:* | ||
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:yubico:piv_tool_manager:*:*:*:*:*:*:*:* | ||
<= 4.1.0.172CPE matchmatch criteria | cpe:2.3:a:yubico:yubikey_smart_card_minidriver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.