Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service with a non-default configuration such as an open sync pool; the issue does NOT affect YubiCloud.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Yubico YubiKey Validation Server 安全漏洞
Vulnerability Description
Yubico YubiKey Validation Server是瑞典Yubico公司的一款身份认证服务器。 YubiKey Validation Server 2.40之前版本中的sync端点存在安全漏洞。远程攻击者可利用该漏洞使用之前用过的一次性密码进行重放攻击。
CVSS Information
N/A
Vulnerability Type
N/A