Description

Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.

INFO

Published Date :

2024-09-03T00:00:00.000Z

Last Modified :

2025-03-17T17:51:54.621Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-45678 vulnerability.

Vendors Products
Yubico
  • Security Key C Nfc By Yubico
  • Security Key C Nfc By Yubico Firmware
  • Security Key Nfc By Yubico
  • Security Key Nfc By Yubico Firmware
  • Yubihsm 2
  • Yubihsm 2 Fips
  • Yubihsm 2 Fips Firmware
  • Yubihsm 2 Firmware
  • Yubikey 5 Nano
  • Yubikey 5 Nano Fips
  • Yubikey 5 Nano Fips Firmware
  • Yubikey 5 Nano Firmware
  • Yubikey 5 Nfc
  • Yubikey 5 Nfc Fips
  • Yubikey 5 Nfc Fips Firmware
  • Yubikey 5 Nfc Firmware
  • Yubikey 5c
  • Yubikey 5c Fips
  • Yubikey 5c Fips Firmware
  • Yubikey 5c Firmware
  • Yubikey 5c Nano
  • Yubikey 5c Nano Fips
  • Yubikey 5c Nano Fips Firmware
  • Yubikey 5c Nano Firmware
  • Yubikey 5c Nfc
  • Yubikey 5c Nfc Fips
  • Yubikey 5c Nfc Fips Firmware
  • Yubikey 5c Nfc Firmware
  • Yubikey 5ci
  • Yubikey 5ci Fips
  • Yubikey 5ci Fips Firmware
  • Yubikey 5ci Firmware
  • Yubikey Bio
  • Yubikey Bio Firmware
  • Yubikey C Bio
  • Yubikey C Bio Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact