Impact
Improper protection of physical side channels in the Microchip AN1044, AN953, and SW300052 product lines can allow an attacker to recover cryptographic keys during operation, thereby compromising the confidentiality of data managed by those devices. The flaw is classified as CWE‑1300, indicating insufficient side‑channel defenses. Based on the description, the attacker could exploit this leakage to extract private keys.
Affected Systems
The affected vendors are Microchip; the products are AN1044, AN953, and SW300052. AN1044 and AN953 are vulnerable through feature A, while SW300052 is affected in firmware version 2.6.
Risk and Exploitability
The CVSS score is 5.6 and the EPSS score is below 1%, indicating a low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a physical side‑channel attack that requires close proximity to the target device and specialized equipment to measure emissions during cryptographic operations. Because Microchip offers no patch and side‑channel prevention is outside of the product’s intended use, organizations must rely on third‑party countermeasures to mitigate the risk.
OpenCVE Enrichment