PT-2024-31724 · Yubico · Yubikey 5 Series+1

Thomas Roche

·

Published

2024-09-03

·

Updated

2026-04-28

·

CVE-2024-45678

CVSS v3.1

4.2

Medium

VectorAV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Yubico YubiKey 5 Series devices with firmware before 5.7.0 YubiHSM 2 devices with firmware before 2.4.0
Description: The issue allows an ECDSA secret-key extraction attack that requires physical access and expensive equipment. This attack is possible due to a non-constant-time modular inversion for the Extended Euclidean Algorithm, which creates an electromagnetic side channel, also known as the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected. The attack potentially exposes millions to cloning risk.
Recommendations: For Yubico YubiKey 5 Series devices with firmware before 5.7.0, update the firmware to version 5.7.0 or later. For YubiHSM 2 devices with firmware before 2.4.0, update the firmware to version 2.4.0 or later.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2024-45678

Affected Products

Yubihsm 2
Yubikey 5 Series