Description
Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052.

This issue affects AN1044: through A; AN953: through A; SW300052: through 2.6.
Published: 2026-09-12
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Side‑channel leakage of cryptographic keys
Action: Assess Impact
AI Analysis

Impact

Improper protection of physical side channels in Microchip AN1044, AN953, and SW300052 can let an attacker extract sensitive cryptographic material, such as private keys, from a device that is near a threat actor. The weakness, identified as CWE‑1300, results in a moderate confidentiality risk as reflected by the CVSS score of 5.6.

Affected Systems

Affected vendor: Microchip. The products impacted are the AN1044 firmware module, the AN953 firmware module, and the SW300052 development tool. Version information is limited: the SW300052 references version 2.6, while no specific versions are listed for AN1044 and AN953. These modules are typically deployed in embedded systems that perform cryptographic operations.

Risk and Exploitability

The EPSS score is below 1 %, indicating that exploitation is currently considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require physical proximity to the target device, specialized side‑channel measurement equipment, and a high level of technical skill. While the CVSS base score of 5.6 denotes moderate severity, the practical difficulty of successfully delivering an attack remains high due to these prerequisites.

Generated by OpenCVE AI on September 13, 2026 at 02:15 UTC.

Remediation

Vendor Solution

None. Side-channel prevention is outside of intended use of product.


OpenCVE Recommended Actions

  • Implement stringent physical security measures that prevent unauthorized proximity to devices using AN1044, AN953, or SW300052.
  • Apply hardware countermeasures such as electromagnetic shielding, active noise generation, or other side‑channel mitigation techniques to reduce leakage.
  • If the application is security‑critical, replace the affected modules with cryptographic implementations that have proven side‑channel resistance.

Generated by OpenCVE AI on September 13, 2026 at 02:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052. This issue affects AN1044: through A; AN953: through A; SW300052: through 2.6.
Title Side-channel attack of AN1044/AN953/SW300052 cryptographic algorithms
Weaknesses CWE-1300
References
Metrics cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Microchip

Published:

Updated: 2026-09-12T09:26:05.932Z

Reserved: 2026-09-11T05:25:06.717Z

Link: CVE-2026-89172

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-12T10:16:36.317

Modified: 2026-09-12T10:16:36.317

Link: CVE-2026-89172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T02:15:17Z

Weaknesses
  • CWE-1300

    Improper Protection of Physical Side Channels