4.2

CVE-2024-45678

Medienbericht

Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
YubicoYubikey 5c Nfc Firmware Version < 5.7
   YubicoYubikey 5c Nfc Version-
YubicoYubikey 5 Nfc Firmware Version < 5.7
   YubicoYubikey 5 Nfc Version-
YubicoYubikey 5c Firmware Version < 5.7
   YubicoYubikey 5c Version-
YubicoYubikey 5 Nano Firmware Version < 5.7
   YubicoYubikey 5 Nano Version-
YubicoYubikey 5c Nano Firmware Version < 5.7
   YubicoYubikey 5c Nano Version-
YubicoYubikey 5ci Firmware Version < 5.7
   YubicoYubikey 5ci Version-
YubicoYubikey 5 Nfc Fips Firmware Version < 5.7
   YubicoYubikey 5 Nfc Fips Version-
YubicoYubikey 5c Nfc Fips Firmware Version < 5.7
   YubicoYubikey 5c Nfc Fips Version-
YubicoYubikey 5c Fips Firmware Version < 5.7
   YubicoYubikey 5c Fips Version-
YubicoYubikey 5 Nano Fips Firmware Version < 5.7
   YubicoYubikey 5 Nano Fips Version-
YubicoYubikey 5c Nano Fips Firmware Version < 5.7
   YubicoYubikey 5c Nano Fips Version-
YubicoYubikey 5ci Fips Firmware Version < 5.7
   YubicoYubikey 5ci Fips Version-
YubicoYubikey C Bio Firmware SwEditionfido Version < 5.7.2
   YubicoYubikey C Bio Version- SwEditionfido
YubicoYubikey Bio Firmware SwEditionfido Version < 5.7.2
   YubicoYubikey Bio Version- SwEditionfido
YubicoYubihsm 2 Fips Firmware Version < 2.4.0
   YubicoYubihsm 2 Fips Version2.2
YubicoYubihsm 2 Firmware Version < 2.4.0
   YubicoYubihsm 2 Version2.3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.077
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.2 0.5 3.6
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.2 0.5 3.6
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-203 Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.