CVE-2021-28484 is a denial-of-service vulnerability affecting Yubico yubihsm-connector versions prior to 3.0.1, specifically within the /api/connector endpoint handler. An unauthenticated attacker can send a malformed, short request (0-2 bytes) to the connector, causing it to enter an infinite loop while awaiting data from the YubiHSM, thereby preventing further operations until a restart. Rated High (CVSS 7.5), this vulnerability has a network attack vector, low attack complexity, and high availability impact, with no confidentiality or integrity impact. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.1CPE matchmatch criteria | cpe:2.3:a:yubico:yubihsm_connector:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.