Description
Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052.

This issue affects AN1044: through A; AN953: through A; SW300052: through 2.6.
Published: 2026-09-12
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Side‑channel key leakage
Action: Deploy Countermeasures
AI Analysis

Impact

Improper protection of physical side channels in the Microchip AN1044, AN953, and SW300052 product lines can allow an attacker to recover cryptographic keys during operation, thereby compromising the confidentiality of data managed by those devices. The flaw is classified as CWE‑1300, indicating insufficient side‑channel defenses. Based on the description, the attacker could exploit this leakage to extract private keys.

Affected Systems

The affected vendors are Microchip; the products are AN1044, AN953, and SW300052. AN1044 and AN953 are vulnerable through feature A, while SW300052 is affected in firmware version 2.6.

Risk and Exploitability

The CVSS score is 5.6 and the EPSS score is below 1%, indicating a low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a physical side‑channel attack that requires close proximity to the target device and specialized equipment to measure emissions during cryptographic operations. Because Microchip offers no patch and side‑channel prevention is outside of the product’s intended use, organizations must rely on third‑party countermeasures to mitigate the risk.

Generated by OpenCVE AI on September 15, 2026 at 18:30 UTC.

Remediation

Vendor Solution

None. Side-channel prevention is outside of intended use of product.


OpenCVE Recommended Actions

  • Microchip offers no patch for this vulnerability; side‑channel prevention is outside the intended use of the products.
  • Implement electromagnetic shielding, noise injection, or algorithmic masking in device hardware or firmware to mitigate side‑channel leakage.
  • Enforce strict physical security controls, such as lockable enclosures and access restrictions, to limit unauthorized proximity to devices using AN1044, AN953, or SW300052.
  • Consider migrating to cryptographic modules or HSMs that incorporate proven side‑channel resistance, or request firmware updates from Microchip that address side‑channel protections.

Generated by OpenCVE AI on September 15, 2026 at 18:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Microchip
Microchip an1044
Microchip an953
Microchip sw300052
Vendors & Products Microchip
Microchip an1044
Microchip an953
Microchip sw300052

Sat, 12 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052. This issue affects AN1044: through A; AN953: through A; SW300052: through 2.6.
Title Side-channel attack of AN1044/AN953/SW300052 cryptographic algorithms
Weaknesses CWE-1300
References
Metrics cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Microchip

Published:

Updated: 2026-09-14T13:00:29.366Z

Reserved: 2026-09-11T05:25:06.717Z

Link: CVE-2026-89172

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:08.812Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-12T10:16:36.317

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-89172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:45:18Z

Weaknesses
  • CWE-1300

    Improper Protection of Physical Side Channels