Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.
Conclusion & alert: CVE-2024-45678 is rated Low Risk (25.5/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.33%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.24% | 0.33% | +0.08% |
| 2 | 2026-04-28 | 0.25% | 0.24% | -0.01% |
| 3 | 2026-04-21 | — | 0.25% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.2 | 3.1 | MEDIUM |
|
0.5 | 3.6 | [email protected] |
| 4.2 | 3.1 | MEDIUM |
|
0.5 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| yubico | yubikey_5c_nfc_firmware | < 5.7 | cpe:2.3:o:yubico:yubikey_5c_nfc_firmware:*:*:*:*:*:*:*:* |
| yubico | yubikey_5_nfc_firmware | < 5.7 | cpe:2.3:o:yubico:yubikey_5_nfc_firmware:*:*:*:*:*:*:*:* |
| yubico | yubikey_5c_firmware | < 5.7 | cpe:2.3:o:yubico:yubikey_5c_firmware:*:*:*:*:*:*:*:* |
| yubico | yubikey_5_nano_firmware | < 5.7 | cpe:2.3:o:yubico:yubikey_5_nano_firmware:*:*:*:*:*:*:*:* |
| yubico | yubikey_5c_nano_firmware | < 5.7 | cpe:2.3:o:yubico:yubikey_5c_nano_firmware:*:*:*:*:*:*:*:* |
| yubico | yubikey_5ci_firmware | < 5.7 | cpe:2.3:o:yubico:yubikey_5ci_firmware:*:*:*:*:*:*:*:* |
| yubico | yubikey_5_nfc_fips_firmware | < 5.7 | cpe:2.3:o:yubico:yubikey_5_nfc_fips_firmware:*:*:*:*:*:*:*:* |
| yubico | yubikey_5c_nfc_fips_firmware | < 5.7 | cpe:2.3:o:yubico:yubikey_5c_nfc_fips_firmware:*:*:*:*:*:*:*:* |
| yubico | yubikey_5c_fips_firmware | < 5.7 | cpe:2.3:o:yubico:yubikey_5c_fips_firmware:*:*:*:*:*:*:*:* |
| yubico | yubikey_5_nano_fips_firmware | < 5.7 | cpe:2.3:o:yubico:yubikey_5_nano_fips_firmware:*:*:*:*:*:*:*:* |
| yubico | yubikey_5c_nano_fips_firmware | < 5.7 | cpe:2.3:o:yubico:yubikey_5c_nano_fips_firmware:*:*:*:*:*:*:*:* |
| yubico | yubikey_5ci_fips_firmware | < 5.7 | cpe:2.3:o:yubico:yubikey_5ci_fips_firmware:*:*:*:*:*:*:*:* |
| yubico | yubikey_c_bio_firmware | < 5.7.2 | cpe:2.3:o:yubico:yubikey_c_bio_firmware:*:*:*:*:fido:*:*:* |
| yubico | yubikey_bio_firmware | < 5.7.2 | cpe:2.3:o:yubico:yubikey_bio_firmware:*:*:*:*:fido:*:*:* |
| yubico | security_key_nfc_by_yubico_firmware | < 5.7 | cpe:2.3:o:yubico:security_key_nfc_by_yubico_firmware:*:*:*:*:*:*:*:* |
| yubico | security_key_c_nfc_by_yubico_firmware | < 5.7 | cpe:2.3:o:yubico:security_key_c_nfc_by_yubico_firmware:*:*:*:*:*:*:*:* |
| yubico | yubihsm_2_fips_firmware | < 2.4.0 | cpe:2.3:o:yubico:yubihsm_2_fips_firmware:*:*:*:*:*:*:*:* |
| yubico | yubihsm_2_firmware | < 2.4.0 | cpe:2.3:o:yubico:yubihsm_2_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://arstechnica.com/security/2024/09/yubikeys-are-vulnerable-to-cloning-attacks-thanks-to-newly-discovered-side-channel/ | Press/Media Coverage |
| https://news.ycombinator.com/item?id=41434500 | Issue Tracking |
| https://ninjalab.io/eucleak/ | Third Party Advisory |
| https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf | Technical Description |
| https://support.yubico.com/hc/en-us/articles/15705749884444 | Mitigation Third Party Advisory |
| https://www.yubico.com/support/security-advisories/ysa-2024-03/ | Vendor Advisory |