CVE-2025-23013 Details
Description
In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.
A local privilege escalation vulnerability has been identified in Yubico's pam-u2f package, prior to version 1.3.1. This Pluggable Authentication Module (PAM) allows authentication using YubiKeys or other FIDO-compliant devices on macOS and Linux. The vulnerability arises from improper handling of PAM_IGNORE return values in the pam_sm_authenticate() function, which can lead to an authentication bypass in certain configurations. An unprivileged user may exploit this issue, and depending on the setup, knowledge of the user's password might also be required.
Users are advised to upgrade to pam-u2f version 1.3.1 or later. For Debian users, the updated version is available in the Debian LTS repository. Yubico also recommends checking the version of pam-u2f installed and upgrading if necessary.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 15, 2025CISA-ADP
Assessed Jan 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2025/02/msg00001.html | CVE | AdvisoryMailing ListRemedyVendor |
| http://www.openwall.com/lists/oss-security/2025/01/15/1 | CVE | Mailing ListTechnical Description |
| http://www.openwall.com/lists/oss-security/2025/01/16/2 | CVE | Mailing ListTechnical Description |
| http://www.openwall.com/lists/oss-security/2025/01/16/3 | CVE | Mailing ListTechnical Description |
| http://www.openwall.com/lists/oss-security/2025/01/16/4 | CVE | Mailing ListTechnical Description |
| http://www.openwall.com/lists/oss-security/2025/01/16/5 | CVE | Mailing ListTechnical Description |
| https://www.yubico.com/support/security-advisories/ysa-2025-01/ | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-394 | Unexpected Status Code or Return Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Yubico pam-u2f | < 1.3.1 (semver) |
CPE
Remediation
| |
| Debian | All versions |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Feb 3, 2025 | CVE Modified | CVE |
| Jan 16, 2025 | CVE Modified | CVE |
| Jan 16, 2025 | CVE Modified | CVE |
| Jan 16, 2025 | CVE Modified | CVE |
| Jan 16, 2025 | CVE Modified | CVE |
| Jan 15, 2025 | CVE Modified | CVE |
| Jan 15, 2025 | New CVE Received | [email protected] |
Volerion