Use of a Cryptographic Primitive with a Risky Implementation
CVE-2023-51392
Summary
Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.
- LOW
- LOCAL
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-1240 - Use of a Cryptographic Primitive with a Risky Implementation
To fulfill the need for a cryptographic primitive, the product implements a cryptographic algorithm using a non-standard, unproven, or disallowed/non-compliant cryptographic implementation.
References
Advisory Timeline
- Published