We detect you are using an unsupported browser. For the best experience, please visit the site using Chrome, Firefox, Safari, or Edge. X
Maximize Your Experience: Reap the Personalized Advantages by Completing Your Profile to Its Fullest. Update Here
Stay in the loop with the latest from Microchip. Update your profile while you are at it. Update Here
Complete your profile to access more resources. Update Here

PSIRT-128: Side-Channel Attack of AN1044/AN953/SW300052 Cryptographic Algorithms

Vulnerability Details


Date of Disclosure: 09/14/2026

Affected Product:   AN1044, AN953, SW30052, Microchip Library of Applications Crypto, MCC Data Encryption Routines

  • Vulnerability Type:  Information disclosure
  • CVE Identifier: CVE-2026-89172
  • CVSS Score: 5.6 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
  • Vulnerability Description:
    • Implementations do not include side-channel resistance which can result in key and data extraction
  • Affected Versions:  
    • All versions
  • Vulnerability Status:
    • Side-channel prevention outside of intended use of product

Risk Assessment


Exploitation of vulnerability could allow an attacker to gain keys stored inside of device memory. Attackers must have physical access to the system and perform side-channel attacks to extract information.

Mitigation


None. Side-channel prevention is outside the intended use of the product.

Acknowledgements


Reported by Daniel Würsch

Recommendations


When using symmetric or private keys in a system or component that is not physically secured and impact of loss of keys is larger than the loss of the system or component itself, use a solution that implements physical and side-channel attack countermeasures. 

Live Chat

Need Help?

Privacy Policy