CVE-2024-45678: Medium severity yubico yubikey 5c nfc firmware vulnerability

Published Sep 3, 2024
·
Updated

Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.

Affected Software

36 affected components
All of the following
Yubico Yubikey 5c Nfc Firmware<5.7
Yubico Yubikey 5c Nfc
All of the following
Yubico Yubikey 5 Nfc Firmware<5.7
Yubico YubiKey 5 NFC
All of the following
Yubico Yubikey 5c Firmware<5.7
Yubico Yubikey 5c
All of the following
Yubico Yubikey 5 Nano Firmware<5.7
Yubico Yubikey 5 Nano
All of the following
Yubico Yubikey 5c Nano Firmware<5.7
Yubico Yubikey 5c Nano
All of the following
Yubico Yubikey 5ci Firmware<5.7
Yubico Yubikey 5ci
All of the following
Yubico Yubikey 5 Nfc Fips Firmware<5.7
Yubico Yubikey 5 Nfc Fips
All of the following
Yubico Yubikey 5c Nfc Fips Firmware<5.7
Yubico Yubikey 5c Nfc Fips
All of the following
Yubico Yubikey 5c Fips Firmware<5.7
Yubico Yubikey 5c Fips
All of the following
Yubico Yubikey 5 Nano Fips Firmware<5.7
Yubico Yubikey 5 Nano Fips
All of the following
Yubico Yubikey 5c Nano Fips Firmware<5.7
Yubico Yubikey 5c Nano Fips
All of the following
Yubico Yubikey 5ci Fips Firmware<5.7
Yubico Yubikey 5ci Fips
All of the following
Yubico Yubikey C Bio Firmware<5.7.2
Yubico Yubikey C Bio
All of the following
Yubico Yubikey Bio Firmware<5.7.2
Yubico Yubikey Bio
All of the following
Yubico Security Key Nfc By Yubico Firmware<5.7
Yubico Security Key Nfc By Yubico
All of the following
Yubico Security Key C Nfc By Yubico Firmware<5.7
Yubico Security Key C Nfc By Yubico
All of the following
Yubico Yubihsm 2 Fips Firmware<2.4.0
Yubico Yubihsm 2 Fips=2.2
All of the following
Yubico Yubihsm 2 Firmware<2.4.0
Yubico YubiHSM 2=2.3.2

Event History

Sep 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-45678?

The severity of CVE-2024-45678 is classified as critical due to its potential for sensitive data leakage through physical attacks.

2

How do I fix CVE-2024-45678?

To fix CVE-2024-45678, update the firmware of the affected Yubico devices to version 5.7.0 or later for YubiKey and 2.4.0 or later for YubiHSM 2.

3

What devices are affected by CVE-2024-45678?

CVE-2024-45678 affects YubiKey 5 Series devices with firmware prior to 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0.

4

What is the exploit method for CVE-2024-45678?

The exploit method for CVE-2024-45678 involves an ECDSA secret-key extraction attack that requires physical access and specialized equipment.

5

Is physical access required to exploit CVE-2024-45678?

Yes, physical access is required to exploit CVE-2024-45678 due to the nature of the electromagnetic side channel attack.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203