CVE-2026-6923
Nuvoton - CWE-1300: Improper Protection of Physical Side Channels
CVSS Score
3.8
EPSS Score
0.0%
EPSS Percentile
0th
A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.
| CWE | CWE-1300 |
| Vendor | nuvoton |
| Product | npct7xx |
| Published | May 14, 2026 |
| Last Updated | May 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for nuvoton npct7xx
Be the first to know when new low vulnerabilities affecting nuvoton npct7xx are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N Attack Vector
Physical
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Nuvoton / NPCT7xx
all versions below 7.2.4.0
References
Credits
Robin Muller, Roman Korkikian - uSec