PT-2026-52556 · Sixg301 · Sixg301
CVE-2026-4930
·
Published
2026-06-25
·
Updated
2026-06-25
CVSS v4.0
7.1
High
| Vector | AV:P/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
SiXG301 (affected versions not specified)
Description
SYMCRYPTO, the host side hardware engine of the SiXG301 accessed by the PSA crypto library, accelerates symmetric cryptographic operations such as AES encryption, decryption, and hashing. If an attacker achieves code execution on the device, they can force specific seed values to weaken Differential Power Analysis (DPA) countermeasures by reducing entropy. This makes the keys loaded on SYMCRYPTO more susceptible to extraction via DPA attacks, a technique used to recover secret keys by analyzing the power consumption of a hardware device during cryptographic operations.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sixg301