Description
Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injection.

This issue affects SAMA5D4.
Published: 2026-08-24
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Hardware Fault Injection
Action: Assess Impact
AI Analysis

Impact

The Microchip SAMA5D4 microcontroller is vulnerable due to insufficient protection against voltage and clock glitches, which can be exploited to induce hardware fault injection. This flaw is classified as CWE‑1247 and allows an attacker to cause the device to transition into a corrupted state, potentially bypassing or subverting normal security controls. The exact consequence of a successful fault injection is not detailed in the advisory, but the flaw raises the risk to confidentiality, integrity, or availability of any system relying on the SAMA5D4.

Affected Systems

The vulnerability affects all devices in the Microchip SAMA5D4 series. No sub‑model or firmware version was specified, so every SAMA5D4 implementation should be considered potentially impacted until a vendor‑issued mitigation is available.

Risk and Exploitability

The likely attack vector is physical, as the flaw requires voltage or clock manipulation to trigger the fault. Based on the description, it is inferred that an attacker must have direct hardware access or the ability to deliver spoofed signals to the device. The EPSS score is not available, the CVSS score is 7.3, and the vulnerability is not listed in CISA KEV, indicating a high severity with a somewhat indeterminate exploitation likelihood pending an active foothold.

Generated by OpenCVE AI on August 24, 2026 at 19:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Microchip to determine if a firmware or hardware update that enhances voltage and clock glitch protection is available.
  • If a vendor‑issued update is released, apply it to affected devices as soon as possible.
  • Implement runtime protection such as watchdog timers, voltage monitoring, and redundant clock checks to detect and mitigate the impact of a fault injection event.

Generated by OpenCVE AI on August 24, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microchip
Microchip sama5d4
Vendors & Products Microchip
Microchip sama5d4
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injection. This issue affects SAMA5D4.
Title SAMA5D44 Fault Injection Vulnerability
Weaknesses CWE-1247
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Microchip Sama5d4
cve-icon MITRE

Status: PUBLISHED

Assigner: Microchip

Published:

Updated: 2026-08-24T20:18:42.750Z

Reserved: 2026-07-30T05:06:19.951Z

Link: CVE-2026-18349

cve-icon Vulnrichment

Updated: 2026-08-24T20:18:38.380Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T17:17:21.740

Modified: 2026-08-31T19:33:11.197

Link: CVE-2026-18349

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:10:20Z

Weaknesses
  • CWE-1247

    Improper Protection Against Voltage and Clock Glitches