CVE-2025-14972 MEDIUM

CVE-2025-14972: Insufficient DPA countermeasure reseeding

Vendor Silabs.com
Product Simplicity SDK
Weakness CWE-331
Published May 15, 2026
Last update May 15, 2026

CVSS base score

4.1/10
Attack vector Physical
Attack complexity High
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually repeat. * KSU keys using SYMCRYPTO will be impacted by this vulnerability.

Key dates

02Disclosure timeline

May 15, 2026 CVE published
May 15, 2026 Record updated