Description
Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attacks, resulting in high confidentiality and integrity impact due to the exposure of private cryptographic keys.
Published: 2026-08-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An observable timing discrepancy within the ECDSA secp256k1 component of AMD Vitis libraries allows a local attacker to perform timing or electromagnetic emanation analysis to recover private cryptographic keys, resulting in high confidentiality and integrity impact by exposing confidential key material. The weakness is a cryptographic key confidentiality problem (CWE-208).

Affected Systems

AMD Vitis Libraries – Security Module and AMD Vitis Unified Installer for FPGAs & Adaptive SoCs in Windows. Specific version information was not supplied; the vulnerability applies to all releases that include the affected ECDSA component.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity, but the EPSS score of less than 1% shows that exploitation is unlikely in the near term. The vendor does not list this issue in the CISA KEV catalog. The attack vector is local; an attacker must have physical or privileged local access to observe timing or EM emissions. No widespread exploits have been reported.

Generated by OpenCVE AI on August 12, 2026 at 21:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Conduct a risk assessment to determine whether the AMD Vitis ECDSA secp256k1 component is used in your environment.
  • Restrict local physical and administrative access to systems that run the affected Vitis libraries to reduce the window for timing or EM attacks.
  • Apply any future vendor patches or updates for the AMD Vitis libraries once they are released to eliminate the timing discrepancy.

Generated by OpenCVE AI on August 12, 2026 at 21:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd vitis Libraries
Amd vitis Unified Installer
Vendors & Products Amd
Amd vitis Libraries
Amd vitis Unified Installer

Wed, 12 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Timing Side-Channel Exposure in AMD Vitis ECDSA Secp256k1 Module

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attacks, resulting in high confidentiality and integrity impact due to the exposure of private cryptographic keys.
Weaknesses CWE-208
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Amd Vitis Libraries Vitis Unified Installer
cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2026-08-12T13:05:46.102Z

Reserved: 2026-05-01T18:15:57.425Z

Link: CVE-2026-43606

cve-icon Vulnrichment

Updated: 2026-08-12T13:05:42.599Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:58.837

Modified: 2026-08-12T20:50:58.370

Link: CVE-2026-43606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:54:12Z

Weaknesses
  • CWE-208

    Observable Timing Discrepancy