SB2024090406 - ECDSA private key recovery in Yubico YubiKey and Security Key series
Published: September 4, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Observable discrepancy (CVE-ID: N/A)
The vulnerability allows an attacker to recover an ECDSA private key.
The vulnerability exists due to observable discrepancy within the Infineon’s cryptographic library used by the YubiKey 5 Series and Security Key Series firmware. An attacker with physical access to the token can perform a side-channel attack to recover the ECDSA private key and compromise the hardware token.
Remediation
Install update from vendor's website.