Junglewise Threat Intelligence

CVE-2025-14972: Silicon Labs SixG301xxx insufficient entropy in SYMCRYPTO DPA countermeasures

CVE-2025-14972 · Severity: info · CVSS 4.1 · Published 2026-05-15

Vendors: Silicon Labs.

Executive brief

Silicon Labs SixG301xxx hardware devices contain a security weakness in their cryptographic engine, which is responsible for protecting sensitive digital keys. The mechanism intended to prevent sophisticated physical attacks (Differential Power Analysis) uses predictable data that eventually repeats. If an attacker has physical access to the device, they could potentially bypass these protections to extract secret cryptographic keys, compromising the device's identity and secure communications.

Technical details

A vulnerability exists in the SYMCRYPTO engine of Silicon Labs SixG301xxx devices due to insufficient entropy (CWE-331) in its Differential Power Analysis (DPA) countermeasures. The countermeasures rely on random values that are not sufficiently random and eventually repeat, undermining the side-channel resistance of the hardware. An attacker with physical access to the device can exploit this repetition to perform DPA attacks and recover Key Storage Unit (KSU) keys. This is a hardware-level vulnerability affecting cryptographic operations that utilize the SYMCRYPTO engine. Mitigation typically requires hardware or firmware updates from the vendor to improve the randomness of the countermeasure implementation.

Affected products

  • Silicon Labs SixG301xxx devices All versions using SYMCRYPTO engine with KSU keys

Timeline

  • 2026-05-15: advisory: NVD publication date

References