Impact
The Microchip SAMA5D4 microcontroller is vulnerable due to insufficient protection against voltage and clock glitches, which can be exploited to induce hardware fault injection. This flaw is classified as CWE‑1247 and allows an attacker to cause the device to transition into a corrupted state, potentially bypassing or subverting normal security controls. The exact consequence of a successful fault injection is not detailed in the advisory, but the flaw raises the risk to confidentiality, integrity, or availability of any system relying on the SAMA5D4.
Affected Systems
The vulnerability affects all devices in the Microchip SAMA5D4 series. No sub‑model or firmware version was specified, so every SAMA5D4 implementation should be considered potentially impacted until a vendor‑issued mitigation is available.
Risk and Exploitability
The likely attack vector is physical, as the flaw requires voltage or clock manipulation to trigger the fault. Based on the description, it is inferred that an attacker must have direct hardware access or the ability to deliver spoofed signals to the device. The EPSS score is not available, the CVSS score is 7.3, and the vulnerability is not listed in CISA KEV, indicating a high severity with a somewhat indeterminate exploitation likelihood pending an active foothold.
OpenCVE Enrichment