CVE-2018-14780 is an out-of-bounds read vulnerability in the Yubico-Piv smartcard driver, specifically affecting yubico piv_manager, yubico piv_tool, and yubico smart_card_minidriver. The flaw, located in the _ykpiv_fetch_object() function within lib/ykpiv.c, allows a memmove() operation to read beyond the allocated data buffer due to an unchecked length value derived from APDU data. This medium severity vulnerability (CVSS 4.6) has a physical attack vector and could lead to high confidentiality impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.2CPE matchmatch criteria | cpe:2.3:a:yubico:piv_manager:*:*:*:*:*:*:*:* | ||
1.4.2CPE matchmatch criteria | cpe:2.3:a:yubico:piv_manager:1.4.2:*:*:*:*:*:*:* | ||
1.4.2bCPE matchmatch criteria | cpe:2.3:a:yubico:piv_manager:1.4.2b:*:*:*:*:*:*:* | ||
1.4.2cCPE matchmatch criteria | cpe:2.3:a:yubico:piv_manager:1.4.2c:*:*:*:*:*:*:* | ||
1.4.2dCPE matchmatch criteria | cpe:2.3:a:yubico:piv_manager:1.4.2d:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.