📦

pam_module

Vendor: yubico

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 1 Total Indexed
Avg. EPSS 2.02% Exploit Prob.
Latest CVE CVE-2011-4120 Nov 26

Security Vulnerability Index

Page 1 / 1
9.8 CVSS

Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.

EPSS: 2.02%