CVE-2024-45678: Yubico Security Key C Nfc By Yubico Firmware

Medium severity, CVSS 4.2. EPSS: 0.3% chance of exploitation in the next 30 days.

Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.

Affected products

  • Yubico Security Key C Nfc By Yubico Firmware: before 5.7 (fixed in 5.7)
  • Yubico Security Key Nfc By Yubico Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubihsm 2 Fips Firmware: before 2.4.0 (fixed in 2.4.0)
  • Yubico Yubihsm 2 Firmware: before 2.4.0 (fixed in 2.4.0)
  • Yubico Yubikey 5 Nano Fips Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubikey 5 Nano Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubikey 5 Nfc Fips Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubikey 5 Nfc Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubikey 5c Fips Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubikey 5c Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubikey 5c Nano Fips Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubikey 5c Nano Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubikey 5c Nfc Fips Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubikey 5c Nfc Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubikey 5ci Fips Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubikey 5ci Firmware: before 5.7 (fixed in 5.7)
  • Yubico Yubikey Bio Firmware: before 5.7.2 (fixed in 5.7.2)
  • Yubico Yubikey C Bio Firmware: before 5.7.2 (fixed in 5.7.2)

Published 2024-09-03. Last modified 2026-06-17.