CVE-2024-45678
4.2
Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.5 / Impact: 3.6
Source: NVD
Description
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.
Affected (18)
Products: Yubico: Yubikey 5c Nfc Firmware, Yubikey 5 Nfc Firmware, Yubikey 5c Firmware, Yubikey 5 Nano Firmware, Yubikey 5c Nano Firmware, Yubikey 5ci Firmware, Yubikey 5 Nfc Fips Firmware, Yubikey 5c Nfc Fips Firmware, Yubikey 5c Fips Firmware, Yubikey 5 Nano Fips Firmware, Yubikey 5c Nano Fips Firmware, Yubikey 5ci Fips Firmware, Yubikey C Bio Firmware, Yubikey Bio Firmware, Security Key Nfc By Yubico Firmware, Security Key C Nfc By Yubico Firmware, Yubihsm 2 Fips Firmware, Yubihsm 2 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey 5c Nfc | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey 5 Nfc | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey 5c | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey 5 Nano | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey 5c Nano | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey 5ci | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey 5 Nfc Fips | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey 5c Nfc Fips | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey 5c Fips | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey 5 Nano Fips | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey 5c Nano Fips | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey 5ci Fips | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7.2 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey C Bio | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7.2 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubikey Bio | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Security Key Nfc By Yubico | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7 |
| Running on/with | Platform Versions |
|---|---|
Yubico Security Key C Nfc By Yubico | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.4.0 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubihsm 2 Fips | Version 2.2 |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.4.0 |
| Running on/with | Platform Versions |
|---|---|
Yubico Yubihsm 2 | Version 2.3.2 |
References (6)
Source: cve@mitre.org
Press/Media Coverage
Source: cve@mitre.org
Technical Description
Source: cve@mitre.org
MitigationThird Party Advisory
Timeline
No history available yet.