CVE-2025-14972 PUBLISHED

Insufficient DPA countermeasure reseeding

Assigner: Silabs
Reserved: 19.12.2025 Published: 15.05.2026 Updated: 15.05.2026
  • Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually repeat.
  • KSU keys using SYMCRYPTO will be impacted by this vulnerability.

Metrics

CVSS Vector: CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 4.1

Product Status

Vendor silabs.com
Product Simplicity SDK
Versions Default: unaffected
  • affected from 0 to *.* (incl.)

References

Problem Types

  • CWE-331 Insufficient entropy CWE

Impacts

  • CAPEC-212 Functionality Misuse