CVE-2023-39908
14.08.2023, 19:15
The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.Enginsight
Vendor | Product | Version |
---|---|---|
yubico | yubihsm_2_sdk | 𝑥 < 2023.08 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration