PT-2024-31724 · Yubico · Yubikey 5 Series+1
Thomas Roche
·
Published
2024-09-03
·
Updated
2026-04-28
·
CVE-2024-45678
CVSS v3.1
4.2
Medium
| Vector | AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Yubico YubiKey 5 Series devices with firmware before 5.7.0
YubiHSM 2 devices with firmware before 2.4.0
Description:
The issue allows an ECDSA secret-key extraction attack that requires physical access and expensive equipment. This attack is possible due to a non-constant-time modular inversion for the Extended Euclidean Algorithm, which creates an electromagnetic side channel, also known as the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected. The attack potentially exposes millions to cloning risk.
Recommendations:
For Yubico YubiKey 5 Series devices with firmware before 5.7.0, update the firmware to version 5.7.0 or later.
For YubiHSM 2 devices with firmware before 2.4.0, update the firmware to version 2.4.0 or later.
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yubihsm 2
Yubikey 5 Series