Neuer Eucleak-Angriff lässt Bedrohungsakteure YubiKey FIDO-Schlüssel klonen

Teilen:

A new “EUCLEAK” flaw found in FIDO devices using the Infineon SLE78 security microcontroller, like Yubico’s YubiKey 5 Series, allows attackers to extract Elliptic Curve Digital Signature Algorithm (ECDSA) secret keys and clone the FIDO device.

NinjaLab’s Thomas Roche, who discovered the flaw and devised the EUCLEAK side-channel attack, notes that the side channel can retrieve an ECDSA secret key using EM acquisitions.

However, the attack requires extended physical access, specialized equipment, and a high level of understanding of electronics and cryptography.

These prerequisites significantly mitigate the risk, limiting it mostly to attacks from highly sophisticated, state-sponsored threat actors against high-value targets. With that said, EUCLEAK is not considered a threat to general users, even to those who use theoretically vulnerable devices.

In 2021, Roche found a side-channel attack that targeted Google Titan security keys, allowing him to extract the ECDSA private key and clone the device.

Yubico responds to EUCLEAK

The flaw impacts YubiKey 5 Series devices running firmware versions older than 5.7.0, which uses Infineon’s flawed cryptographic library.

The models impacted by EUCLEAK are:

  • YubiKey 5 Series versions prior to 5.7
  • YubiKey 5 FIPS Series prior to 5.7
  • YubiKey 5 CSPN Series prior to 5.7
  • YubiKey Bio Series versions prior to 5.7.2
  • Security Key Series all versions prior to 5.7
  • YubiHSM 2 versions prior to 2.4.0
  • YubiHSM 2 FIPS versions prior to 2.4.0

The vendor rated the issue as moderate, assigning a CVSS score of only 4.9, which reflects its low risk.

Also, Yubico notes in its advisory that attackers attempting to recover credentials from impacted keys would require the user PIN or biometric verification for full exploitation, making successful attacks even harder.

YubiKey owners can check the firmware version of the security keys using YubiKey Manager oder YubiKey Authenticator.

Unfortunately, if you are using a vulnerable version, there is no way to upgrade the firmware to the latest 5.7.0 (YubiKey) or 2.4.0 (YubiHSM) versions to mitigate this flaw.

The vendor recommends using RSA signing keys instead of elliptic curve (ECC) signing keys and limiting the maximum session duration from the identity provider settings to require more frequent FIDO authentications.

Other impacted products

NinjaLab confirmed that EUCLEAK also impacts Infineon TPMs (SLB96xx), used for secure boot, authentication, and cryptographic operations, and Infineon’s Optiga Trust M security microcontroller, used in IoT devices.

Infineon TPMs are used in the smart enclaves of old (between 2013 and 2018) smartphones and tablets from Samsung and OnePlus, and also some dated (from mid-2010s) laptop models from Lenovo, Acer, Dell, HP, and LG.

The Feitian A22 JavaCard, used in smart cards and authentication systems, is also impacted by using the Infineon SLE78 microcontroller.

ADVERTISING

Other potentially impacted devices include e-passports, cryptocurrency hardware wallets (cold wallets), IoT devices, and any FIDO device that uses Infineon’s SLE78.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:34 pm, Juni 23, 2025
Wetter-Symbol 22°C
L: 21° | H: 24°
broken clouds
Luftfeuchtigkeit: 41 %
Druck: 1014 mb
Wind: 17 mph W
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 53%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 14 mph 49 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 23°°C 0.2 mm 20% 14 mph 80 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 9 mph 89 % 1013 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 22°°C 1 mm 100% 14 mph 91 % 1017 mb 0 mm/h
Fr. Juni 27 10:00 pm
Wetter-Symbol
14° | 27°°C 0 mm 0% 16 mph 69 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 13 mph 41 % 1014 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 22°°C 0 mm 0% 14 mph 40 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
17° | 19°°C 0 mm 0% 10 mph 49 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 9 mph 68 % 1016 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 8 mph 80 % 1014 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 11 mph 75 % 1014 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 12 mph 63 % 1013 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 14 mph 66 % 1013 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€88,404.55
-0.65%
Ethereum(ETH)
€1,966.20
0.37%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.74
0.22%
Solana(SOL)
€117.30
2.47%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.133591
0.27%
Shiba Inu(SHIB)
€0.000010
2.55%
Pepe(PEPE)
€0.000008
1.41%
Peanut das Eichhörnchen(PNUT)
€0.219411
13.10%
Nach oben scrollen