CVE-2019-15809 describes a timing side-channel vulnerability in specific Athena SCS smart cards, including various Athena IDProtect, Valid S/A IDflex V, SafeNet eToken 4300, and TecSec Armored Card models. This flaw, stemming from the use of a "fast" ECDSA signature function in the Atmel Toolbox 00.03.11.05, allows a local attacker to deduce the private key by measuring the duration of numerous signing operations. Rated Medium (CVSS 4.7), the attack requires local access and high attack complexity, but can lead to complete compromise of confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has seen minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
00.03.11.05CPE matchmatch criteria | cpe:2.3:a:microchip:atmel_toolbox:00.03.11.05:*:*:*:*:*:*:* | ||
010b.0352.0005CPE matchmatch criteria | cpe:2.3:o:athena-scs:idprotect:010b.0352.0005:*:*:*:*:*:*:* | ||
010e.1245.0002CPE matchmatch criteria | cpe:2.3:o:athena-scs:idprotect:010e.1245.0002:*:*:*:*:*:*:* | ||
0106.0130.0401CPE matchmatch criteria | cpe:2.3:o:athena-scs:idprotect:0106.0130.0401:*:*:*:*:*:*:* | ||
010b.0352.0005CPE matchmatch criteria | cpe:2.3:o:cryptsoft:s\/a_idflex_v:010b.0352.0005:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.