CVE-2025-3301 describes a vulnerability in Series 2 modules and SoCs where DPA countermeasures are absent for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448. This lack of hardware and software support makes these cryptographic operations susceptible to Differential Power Analysis (DPA) attacks. A successful DPA attack could lead to the exposure of confidential information. The vulnerability has a CVSS score of 1.0 (LOW), indicating a low severity. An attacker would require physical access (AV:P) to the device to perform a DPA attack, and the attack complexity is low (AC:L). The potential impact is limited to the confidentiality of information (VC:L), with no impact on integrity or availability. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered no community discussion or media coverage, suggesting a low level of public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Silabs.Com | Series 2 SoCs And Associated Modules | >= 0, <= all released hardware revisionsCNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.