Side-Channel Attack Vulnerability in Trusted Platform Modules by Various Vendors
CVE-2026-6923

3.8LOW

Key Information:

Vendor

Nuvoton

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-6923?

A vulnerability exists within certain Trusted Platform Modules (TPMs) that can be exploited through a side-channel attack. This type of attack necessitates physical access to the TPM hardware and can allow attackers to extract sensitive Elliptic Curve Diffie-Hellman (ECDH) keys. Such exploitation poses significant security risks, particularly for cryptographic operations relying on these keys. Organizations using impacted TPM versions must take measures to enhance security and mitigate potential threats.

Affected Version(s)

NPCT7xx all versions below 7.2.4.0

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robin Muller, Roman Korkikian - uSec
.