Impact
An observable timing discrepancy within the ECDSA secp256k1 component of AMD Vitis libraries allows a local attacker to perform timing or electromagnetic emanation analysis to recover private cryptographic keys, resulting in high confidentiality and integrity impact by exposing confidential key material. The weakness is a cryptographic key confidentiality problem (CWE-208).
Affected Systems
AMD Vitis Libraries – Security Module and AMD Vitis Unified Installer for FPGAs & Adaptive SoCs in Windows. Specific version information was not supplied; the vulnerability applies to all releases that include the affected ECDSA component.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, but the EPSS score of less than 1% shows that exploitation is unlikely in the near term. The vendor does not list this issue in the CISA KEV catalog. The attack vector is local; an attacker must have physical or privileged local access to observe timing or EM emissions. No widespread exploits have been reported.
OpenCVE Enrichment