CVE-2024-45678: Yubico Security Key C Nfc By Yubico Firmware
Medium severity, CVSS 4.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.
Affected products
- Yubico Security Key C Nfc By Yubico Firmware: before 5.7 (fixed in 5.7)
- Yubico Security Key Nfc By Yubico Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubihsm 2 Fips Firmware: before 2.4.0 (fixed in 2.4.0)
- Yubico Yubihsm 2 Firmware: before 2.4.0 (fixed in 2.4.0)
- Yubico Yubikey 5 Nano Fips Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubikey 5 Nano Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubikey 5 Nfc Fips Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubikey 5 Nfc Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubikey 5c Fips Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubikey 5c Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubikey 5c Nano Fips Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubikey 5c Nano Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubikey 5c Nfc Fips Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubikey 5c Nfc Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubikey 5ci Fips Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubikey 5ci Firmware: before 5.7 (fixed in 5.7)
- Yubico Yubikey Bio Firmware: before 5.7.2 (fixed in 5.7.2)
- Yubico Yubikey C Bio Firmware: before 5.7.2 (fixed in 5.7.2)
Published 2024-09-03. Last modified 2026-06-17.