PT-2026-52556 · Sixg301 · Sixg301

CVE-2026-4930

·

Published

2026-06-25

·

Updated

2026-06-25

CVSS v4.0

7.1

High

VectorAV:P/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SiXG301 (affected versions not specified)
Description SYMCRYPTO, the host side hardware engine of the SiXG301 accessed by the PSA crypto library, accelerates symmetric cryptographic operations such as AES encryption, decryption, and hashing. If an attacker achieves code execution on the device, they can force specific seed values to weaken Differential Power Analysis (DPA) countermeasures by reducing entropy. This makes the keys loaded on SYMCRYPTO more susceptible to extraction via DPA attacks, a technique used to recover secret keys by analyzing the power consumption of a hardware device during cryptographic operations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4930

Affected Products

Sixg301