First published: Tue Sep 03 2024(Updated: )
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Yubico YubiKey 5C NFC Firmware | <5.7 | |
Yubico YubiKey 5C NFC Firmware | ||
All of | ||
Yubico YubiKey 5C NFC Firmware | <5.7 | |
Yubico YubiKey 5 NFC Firmware | ||
All of | ||
Yubico Yubikey 5c NFC Firmware | <5.7 | |
Yubico YubiKey | ||
All of | ||
Yubico YubiKey 5 Nano Firmware | <5.7 | |
Yubico YubiKey 5 Nano Firmware | ||
All of | ||
Yubico YubiKey 5C Nano FIPS Firmware | <5.7 | |
Yubico YubiKey 5C Nano FIPS | ||
All of | ||
Yubico YubiKey 5Ci FIPS | <5.7 | |
Yubico YubiKey | ||
All of | ||
Yubico YubiKey 5C NFC FIPS Firmware | <5.7 | |
Yubico Security Key NFC | ||
All of | ||
Yubico YubiKey 5C NFC Firmware | <5.7 | |
Yubico YubiKey 5C NFC FIPS Firmware | ||
All of | ||
Yubico YubiKey 5C FIPS | <5.7 | |
Yubico YubiKey 5C FIPS Firmware | ||
All of | ||
Yubico YubiKey 5 Nano Firmware | <5.7 | |
Yubico Yubikey 5 Nano | ||
All of | ||
Yubico YubiKey 5 Nano FIPS Firmware | <5.7 | |
Yubico YubiKey 5C Nano FIPS Firmware | ||
All of | ||
Yubico YubiKey 5Ci FIPS | <5.7 | |
Yubico YubiKey | ||
All of | ||
Yubico YubiKey C Bio Firmware | <5.7.2 | |
Yubico Yubikey C Bio Firmware | ||
All of | ||
Yubico Yubikey C Bio Firmware | <5.7.2 | |
Yubico Yubikey C Bio Firmware | ||
All of | ||
Yubico YubiKey 5C NFC | <5.7 | |
Yubico Security Key NFC by Yubico Firmware | ||
All of | ||
Yubico Security Key C NFC By Yubico | <5.7 | |
Yubico Security Key C NFC | ||
All of | ||
Yubico YubiHSM 2 FIPS | <2.4.0 | |
YubiHSM 2 | =2.2 | |
All of | ||
Yubico YubiHSM 2 | <2.4.0 | |
YubiHSM 2 | =2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-45678 is classified as critical due to its potential for sensitive data leakage through physical attacks.
To fix CVE-2024-45678, update the firmware of the affected Yubico devices to version 5.7.0 or later for YubiKey and 2.4.0 or later for YubiHSM 2.
CVE-2024-45678 affects YubiKey 5 Series devices with firmware prior to 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0.
The exploit method for CVE-2024-45678 involves an ECDSA secret-key extraction attack that requires physical access and specialized equipment.
Yes, physical access is required to exploit CVE-2024-45678 due to the nature of the electromagnetic side channel attack.