Impact
Improper protection of physical side channels in Microchip AN1044, AN953, and SW300052 can let an attacker extract sensitive cryptographic material, such as private keys, from a device that is near a threat actor. The weakness, identified as CWE‑1300, results in a moderate confidentiality risk as reflected by the CVSS score of 5.6.
Affected Systems
Affected vendor: Microchip. The products impacted are the AN1044 firmware module, the AN953 firmware module, and the SW300052 development tool. Version information is limited: the SW300052 references version 2.6, while no specific versions are listed for AN1044 and AN953. These modules are typically deployed in embedded systems that perform cryptographic operations.
Risk and Exploitability
The EPSS score is below 1 %, indicating that exploitation is currently considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require physical proximity to the target device, specialized side‑channel measurement equipment, and a high level of technical skill. While the CVSS base score of 5.6 denotes moderate severity, the practical difficulty of successfully delivering an attack remains high due to these prerequisites.
OpenCVE Enrichment