CVE-2020-10185: Yubico Yubikey One Time Password Validation Server
High severity, CVSS 8.6. EPSS: 1.7% chance of exploitation in the next 30 days.
The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service with a non-default configuration such as an open sync pool; the issue does NOT affect YubiCloud.
Affected products
- Yubico Yubikey One Time Password Validation Server: before 2.40 (fixed in 2.40)
Published 2020-03-05. Last modified 2026-06-17.