CVE detail
CVE-2020-24388 — CVE-2020-24388
Published 2020-10-19 · Modified 2026-06-17 · Vendor yubico · Product yubihsm-shell · Source nvd
HIGH
severity
CVSS-derived band
0.0175
EPSS probability
exploitation probability, 30d
76.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This could be used by an attacker to cause a denial of service.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References