Junglewise Threat Intelligence

CVE-2026-4930: Silicon Labs SiXG301 insufficient entropy in SYMCRYPTO DPA countermeasures

CVE-2026-4930 · Severity: info · CVSS 7.1 · Published 2026-06-25

Vendors: Silicon Labs.

Executive brief

A vulnerability exists in the hardware cryptographic engine of certain Silicon Labs chips used to secure data and communications. If an attacker already has the ability to run code on the device, they can weaken the protections designed to prevent the theft of secret encryption keys. This could allow a sophisticated attacker with physical access to the device to extract sensitive keys, potentially compromising the privacy and security of the entire system.

Technical details

The SYMCRYPTO hardware engine, used by the PSA crypto library for AES and hashing operations on SiXG301 devices, is vulnerable to a reduction in entropy for its Differential Power Analysis (DPA) countermeasures. An attacker who has already achieved high-privilege code execution on the device can force specific seed values, thereby weakening the randomness used to mask cryptographic operations. This makes the device susceptible to side-channel attacks, specifically DPA, which can lead to the extraction of symmetric keys. The vulnerability is tracked as CWE-331 (Insufficient Entropy) and requires physical access to perform the power analysis after the software-based seed manipulation.

Affected products

  • Silicon Labs Simplicity SDK (SiSDK) All versions using SiXG301 SYMCRYPTO engine

Timeline

  • 2026-06-25: disclosed: Initial disclosure by Silicon Labs
  • 2026-06-25: advisory: NVD record published

References