openwall.com
http://www.openwall.com/lists/oss-security/2025/01/15/1 CVE-2025-23013
HIGH
Record summary
CVE-2025-23013 has a selected CVSS score of 7.3 (high).
Description
In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 15, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
pam-u2fBrowse Yubico / pam-u2fDefault status: unaffected | CVE List | Before 1.3.1 | affected |
References
8openwall.com
http://www.openwall.com/lists/oss-security/2025/01/16/2 openwall.com
http://www.openwall.com/lists/oss-security/2025/01/16/3 openwall.com
http://www.openwall.com/lists/oss-security/2025/01/16/4 openwall.com
http://www.openwall.com/lists/oss-security/2025/01/16/5 lists.debian.org
https://lists.debian.org/debian-lts-announce/2025/02/msg00001.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-23013 yubico.com
https://www.yubico.com/support/security-advisories/ysa-2025-01