Observable discrepancy in Yubico products - #VU96776

 

Observable discrepancy in Yubico products - #VU96776

Published: September 4, 2024


Vulnerability identifier: #VU96776
CSH Severity: Low
CVSS v4: 4.1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-203
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to recover an ECDSA private key.

The vulnerability exists due to observable discrepancy within the Infineon’s cryptographic library used by the YubiKey 5 Series and Security Key Series firmware. An attacker with physical access to the token can perform a side-channel attack to recover the ECDSA private key and compromise the hardware token.


Affected software

YubiHSM
YubiKey 5 Series
Security Key Series
YubiKey Bio Series

Remediation

Install updates from vendor's website.

YubiHSM - update to 2.4.0
YubiKey 5 Series - update to 5.7.0
Security Key Series - update to 5.7.0
YubiKey Bio Series - update to 5.7.2

External References

Related Security Bulletins