Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7ccr-fw66-p8jj

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1

Описание

SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptographic operations (AES encryption/decryption and hashing).

DPA Countermeasures on SYMCRYPTO can be weakened (reduced entropy) by forcing certain seed values if an attacker gains code execution capability on the impacted device.

  • Therefore, the keys loaded on SYMCRYPTO may be more vulnerable to extraction through DPA attacks than intended

SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptographic operations (AES encryption/decryption and hashing).

DPA Countermeasures on SYMCRYPTO can be weakened (reduced entropy) by forcing certain seed values if an attacker gains code execution capability on the impacted device.

  • Therefore, the keys loaded on SYMCRYPTO may be more vulnerable to extraction through DPA attacks than intended

EPSS

Процентиль: 1%
0.00101
Низкий

7.1 High

CVSS4

Дефекты

CWE-331

Связанные уязвимости

nvd
около 2 месяцев назад

SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptographic operations (AES encryption/decryption and hashing). DPA Countermeasures on SYMCRYPTO can be weakened (reduced entropy) by forcing certain seed values if an attacker gains code execution capability on the impacted device. * Therefore, the keys loaded on SYMCRYPTO may be more vulnerable to extraction through DPA attacks than intended

EPSS

Процентиль: 1%
0.00101
Низкий

7.1 High

CVSS4

Дефекты

CWE-331