NVD Vulnerability Detail
Search Exploit, PoC
CVE-2024-45678
Summary

Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.

Publication Date Sept. 4, 2024, 5:15 a.m.
Registration Date Sept. 4, 2024, noon
Last Update Sept. 13, 2024, 5:07 a.m.
CVSS3.1 : MEDIUM
スコア 4.2
Vector CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
攻撃元区分(AV) 物理
攻撃条件の複雑さ(AC)
攻撃に必要な特権レベル(PR) 不要
利用者の関与(UI) 不要
影響の想定範囲(S) 変更なし
機密性への影響(C)
完全性への影響(I) なし
可用性への影響(A) なし
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_5c_nfc_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:yubikey_5c_nfc:-:*:*:*:*:*:*:*
Configuration2 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_5_nfc_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:yubikey_5_nfc:-:*:*:*:*:*:*:*
Configuration3 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_5c_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:yubikey_5c:-:*:*:*:*:*:*:*
Configuration4 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_5_nano_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:yubikey_5_nano:-:*:*:*:*:*:*:*
Configuration5 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_5c_nano_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:yubikey_5c_nano:-:*:*:*:*:*:*:*
Configuration6 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_5ci_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:yubikey_5ci:-:*:*:*:*:*:*:*
Configuration7 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_5_nfc_fips_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:yubikey_5_nfc_fips:-:*:*:*:*:*:*:*
Configuration8 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_5c_nfc_fips_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:yubikey_5c_nfc_fips:-:*:*:*:*:*:*:*
Configuration9 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_5c_fips_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:yubikey_5c_fips:-:*:*:*:*:*:*:*
Configuration10 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_5_nano_fips_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:yubikey_5_nano_fips:-:*:*:*:*:*:*:*
Configuration11 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_5c_nano_fips_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:yubikey_5c_nano_fips:-:*:*:*:*:*:*:*
Configuration12 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_5ci_fips_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:yubikey_5ci_fips:-:*:*:*:*:*:*:*
Configuration13 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_c_bio_firmware:*:*:*:*:fido:*:*:* 5.7.2
execution environment
1 cpe:2.3:h:yubico:yubikey_c_bio:-:*:*:*:fido:*:*:*
Configuration14 or higher or less more than less than
cpe:2.3:o:yubico:yubikey_bio_firmware:*:*:*:*:fido:*:*:* 5.7.2
execution environment
1 cpe:2.3:h:yubico:yubikey_bio:-:*:*:*:fido:*:*:*
Configuration15 or higher or less more than less than
cpe:2.3:o:yubico:security_key_nfc_by_yubico_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:security_key_nfc_by_yubico:-:*:*:*:*:*:*:*
Configuration16 or higher or less more than less than
cpe:2.3:o:yubico:security_key_c_nfc_by_yubico_firmware:*:*:*:*:*:*:*:* 5.7
execution environment
1 cpe:2.3:h:yubico:security_key_c_nfc_by_yubico:-:*:*:*:*:*:*:*
Configuration17 or higher or less more than less than
cpe:2.3:o:yubico:yubihsm_2_fips_firmware:*:*:*:*:*:*:*:* 2.4.0
execution environment
1 cpe:2.3:h:yubico:yubihsm_2_fips:2.2:*:*:*:*:*:*:*
Configuration18 or higher or less more than less than
cpe:2.3:o:yubico:yubihsm_2_firmware:*:*:*:*:*:*:*:* 2.4.0
execution environment
1 cpe:2.3:h:yubico:yubihsm_2:2.3.2:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List

JVN Vulnerability Information
複数の Yubico 製品における観測可能な不一致に関する脆弱性
Title 複数の Yubico 製品における観測可能な不一致に関する脆弱性
Summary

yubikey 5c nfc ファームウェア、YubiKey 5 NFC ファームウェア、yubikey 5c ファームウェア等複数の Yubico 製品には、観測可能な不一致に関する脆弱性が存在します。

Possible impacts 情報を取得される可能性があります。
Solution

ベンダアドバイザリまたはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。

Publication Date Sept. 3, 2024, midnight
Registration Date Sept. 13, 2024, 11:48 a.m.
Last Update Sept. 13, 2024, 11:48 a.m.
Affected System
Yubico
security key c nfc by yubico ファームウェア 5.7 未満
security key nfc by yubico ファームウェア 5.7 未満
yubihsm 2 fips ファームウェア 2.4.0 未満
yubihsm 2 ファームウェア 2.4.0 未満
yubikey 5 nano fips ファームウェア 5.7 未満
yubikey 5 nano ファームウェア 5.7 未満
yubikey 5 nfc fips ファームウェア 5.7 未満
YubiKey 5 NFC ファームウェア 5.7 未満
yubikey 5c fips ファームウェア 5.7 未満
yubikey 5c nano fips ファームウェア 5.7 未満
yubikey 5c nano ファームウェア 5.7 未満
yubikey 5c nfc fips ファームウェア 5.7 未満
yubikey 5c nfc ファームウェア 5.7 未満
yubikey 5c ファームウェア 5.7 未満
yubikey 5ci fips ファームウェア 5.7 未満
yubikey 5ci ファームウェア 5.7 未満
yubikey bio ファームウェア 5.7.2 未満
yubikey c bio ファームウェア 5.7.2 未満
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
その他
Change Log
No Changed Details Date of change
1 [2024年09月13日]
  掲載
Sept. 13, 2024, 11:47 a.m.