Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yubico

First CVE: Apr 4, 2018Active for: 8 yearsTotal CVEs: 27
22.0
VTI Score
Low

Yubico develops authentication hardware and software tools—principally the YubiKey line of hardware security keys and supporting management tools such as YubiHSM Shell and PAM modules—that are deployed widely in enterprise identity and access-control environments. The vendor's vulnerability footprint, while modestly sized, clusters around memory-safety and input-validation weaknesses in its credential-management and authentication-protocol implementations, including out-of-bounds reads and writes, improper input validation, and control-flow irregularities. The exposure spans both hardware firmware and host-side software components, reflecting the complexity of cryptographic key handling and secure communication between authentication devices and endpoints. Defenders tracking this vendor should monitor releases for its PAM integrations and YubiHSM management interfaces in particular, as flaws in these attack surfaces can compromise the trust model of the authentication layer. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
0.1
Avg CVEs / Product / Year
Bottom 1%
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Yubico over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 4, 2018
8 years ago
Most Recent CVE
Jan 15, 2025
556 days ago

Products(54 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-4120CRITICAL
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM con
Nov 26, 20199.829NONO
CVE-2020-10185HIGH
The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate
Mar 5, 20208.626NONO
CVE-2019-12210HIGH
In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This lead
Jun 4, 20198.126NONO
CVE-2019-12209HIGH
Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that
Jun 4, 20197.525NONO
CVE-2018-9275HIGH
In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to i
Apr 4, 20188.225NONO
CVE-2025-23013HIGH
In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support auth
Jan 15, 20257.324NONO
CVE-2021-43399HIGH
The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the length of some operations including SSH signing requests, and som
Dec 8, 20217.524NONO
CVE-2021-28484HIGH
An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK before 2021.04). The handler did not validate the length of
Apr 14, 20217.524NONO
CVE-2020-24388HIGH
An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the d
Oct 19, 20207.524NONO
CVE-2020-24387HIGH
An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An inval
Oct 19, 20207.524NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
48%
48%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (3.7%)
Network16 (59.3%)
Unknown0 (0.0%)
Physical8 (29.6%)
Adjacent Network2 (7.4%)
Attack Complexity
Low21 (77.8%)
High6 (22.2%)
Unknown0 (0.0%)
User Interaction
None26 (96.3%)
Unknown0 (0.0%)
Required1 (3.7%)
Privileges Required
Low3 (11.1%)
High2 (7.4%)
None22 (81.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yubico.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yubico — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yubico's Products

View all 2 CNAs →

Top CWEs