CVE-2024-45678: Medium severity yubico yubikey 5c nfc firmware vulnerability
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45678?
The severity of CVE-2024-45678 is classified as critical due to its potential for sensitive data leakage through physical attacks.
How do I fix CVE-2024-45678?
To fix CVE-2024-45678, update the firmware of the affected Yubico devices to version 5.7.0 or later for YubiKey and 2.4.0 or later for YubiHSM 2.
What devices are affected by CVE-2024-45678?
CVE-2024-45678 affects YubiKey 5 Series devices with firmware prior to 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0.
What is the exploit method for CVE-2024-45678?
The exploit method for CVE-2024-45678 involves an ECDSA secret-key extraction attack that requires physical access and specialized equipment.
Is physical access required to exploit CVE-2024-45678?
Yes, physical access is required to exploit CVE-2024-45678 due to the nature of the electromagnetic side channel attack.