DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on all Series 2 modules and SoCs due to a lack of hardware and software support. A successful DPA attack may result in exposure of confidential information. The best practice is to use the impacted crypto curves and operations with ephemeral keys to reduce the number of DPA traces that can be collected.
History

Tue, 29 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Apr 2025 14:00:00 +0000

Type Values Removed Values Added
Description DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on all Series 2 modules and SoCs due to a lack of hardware and software support. A successful DPA attack may result in exposure of confidential information. The best practice is to use the impacted crypto curves and operations with ephemeral keys to reduce the number of DPA traces that can be collected.
Title DPA Countermeasures Unavailable for Certain Cryptographic Operations on Series 2 Devices
Weaknesses CWE-1255
References
Metrics cvssV4_0

{'score': 1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published: 2025-04-29T13:47:42.717Z

Updated: 2025-04-29T14:02:03.494Z

Reserved: 2025-04-04T19:53:07.856Z

Link: CVE-2025-3301

cve-icon Vulnrichment

Updated: 2025-04-29T14:01:53.600Z

cve-icon NVD

Status : Received

Published: 2025-04-29T14:15:32.643

Modified: 2025-04-29T14:15:32.643

Link: CVE-2025-3301

cve-icon Redhat

No data.