PT-2025-14572 · Yubico · Yubikey

CVE-2025-29991

·

Published

2025-04-03

·

Updated

2025-04-03

CVSS v3.1

2.2

Low

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Yubico YubiKey versions 5.4.1 through 5.7.3
Description The issue is related to an incorrect implementation of the FIDO CTAP PIN/UV 2 authentication protocol. Specifically, it uses the signature length from the CTAP PIN/UV 1 protocol, even when the CTAP PIN/UV 2 protocol is chosen, resulting in partial signature verification.
Recommendations For versions 5.4.1 through 5.7.3, update to version 5.7.4 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-29991

Affected Products

Yubikey